CVE-2026-27895

NameCVE-2026-27895
DescriptionLDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ldap-account-manager (PTS)bullseye (security), bullseye8.0.1-0+deb11u1vulnerable
bookworm8.3-1vulnerable
forky, sid, trixie9.0-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ldap-account-managersource(unstable)(unfixed)

Notes

https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-88hf-2cjm-m9g8
https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-w7xq-vjr3-p9cf

Search for package or bug name: Reporting problems