CVE-2026-27895

NameCVE-2026-27895
DescriptionLDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1131370

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ldap-account-manager (PTS)bullseye (security), bullseye8.0.1-0+deb11u1fixed
bookworm8.3-1fixed
forky, trixie9.0-1vulnerable
sid9.5.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ldap-account-managersourcebullseye(not affected)
ldap-account-managersourcebookworm(not affected)
ldap-account-managersource(unstable)9.5.1-11131370

Notes

[bookworm] - ldap-account-manager <not-affected> (Vulnerable code introduced later)
[bullseye] - ldap-account-manager <not-affected> (Vulnerable code introduced later)
https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-88hf-2cjm-m9g8

Search for package or bug name: Reporting problems