CVE-2025-15554 Details
Description
Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.
A vulnerability in Truesec's LAPSWebUI prior to version 2.4 allows for the browser caching of local admin passwords. This issue enables an attacker with access to a workstation to escalate privileges by disclosing these cached passwords. The vulnerability arises because the application did not include proper cache control headers, allowing sensitive information to be stored in the browser cache and potentially accessed by others in shared browsing environments.
Users are advised to update to Truesec LAPSWebUI version 2.4 or later. If an immediate update is not possible, ensure that the web server hosting LAPSWebUI includes the 'Cache-Control: no-store' header in the response.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.reversec.com/advisories/2026/03/admin-passwords-cached-by-browsers-in-truesec-lapswebui | National Cyber Security Centre Finland | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-525 | Use of Web Browser Cache Containing Sensitive Information | National Cyber Security Centre Finland |
Affected Products
| Product | Versions |
|---|---|
| truesec lapswebui | < 2.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | National Cyber Security Centre Finland |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Mar 16, 2026 | New CVE Received | National Cyber Security Centre Finland |