CVE-2025-15552 Details
Description
Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.
A vulnerability exists in Truesec's LAPSWebUI prior to version 2.4, where insufficient session expiration allows an attacker with access to a workstation to escalate privileges by disclosing the local admin password. This issue arises because the application does not invalidate session cookies server-side, enabling prolonged access even after a significant delay. The default browser setting to clear session cookies can be overridden, leading to indefinite login states. Additionally, the application's logout function only disconnects from Entra ID, not from LAPSWebUI itself.
Users are advised to update to LAPSWebUI version 2.4 or later. If an immediate update is not possible, the 'Force Reauth on Password request' setting can be enabled in the server's 'appsettings.json' file to require Entra ID sign-in before displaying passwords.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.reversec.com/advisories/2026/03/long-session-lifetime-in-truesec-lapswebui | National Cyber Security Centre Finland | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | National Cyber Security Centre Finland |
Affected Products
| Product | Versions |
|---|---|
| truesec lapswebui | < 2.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | National Cyber Security Centre Finland |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | Initial Analysis | [email protected] |
| Mar 16, 2026 | New CVE Received | National Cyber Security Centre Finland |