CVE-2026-27895 Details
Description
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.
A vulnerability in the PDF export component of LDAP Account Manager (LAM) versions prior to 9.5 allows for improper validation of uploaded file extensions. This flaw enables the upload of any file type, including PHP files. Exploiting this vulnerability can lead to local file inclusion (LFI) and, when combined with another vulnerability in LAM, remote code execution as the web server user. The issue arises in deployments where users can log into LAM's admin interface or config import.
Users are advised to upgrade to LAM version 9.5. If an upgrade is not possible, the /var/lib/ldap-account-manager/config directory can be made read-only for the web server user to prevent exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-185 | Incorrect Regular Expression | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ldap-account-manager ldap account manager | >= 8.5, < 9.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 23, 2026 | Initial Analysis | [email protected] |
| Mar 18, 2026 | New CVE Received | [email protected] |