Description

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.

INFO

Published Date :

2026-03-17T23:51:26.501Z

Last Modified :

2026-03-18T19:55:14.059Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-27895 vulnerability.

Vendors Products
Ldap-account-manager
  • Ldap Account Manager
Ldapaccountmanager
  • Lam

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact