CVE-2026-102628: Cadmos LTI exposure of sensitive information via debug mode
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APPDEBUG=true, APPENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable Laravel debug mode by changing APP_DEBUG from true to false in the publicly accessible Cadmos LTI environment.
Laravel APP_DEBUG = false
Event History
Frequently Asked Questions
Who could exploit this issue?
Any unauthenticated remote attacker able to reach the publicly accessible Cadmos LTI application could exploit it. Exploitation required sending a GET request that triggered an unhandled exception.
What information could be exposed?
Laravel debug output could disclose the full server environment, including plaintext values from the application's .env configuration variables. The available data does not identify which specific secrets or configuration values were present.
Was authentication or user interaction required?
No. The issue was remotely exploitable without authentication, privileges, or user interaction.
How can I determine whether an instance was affected?
An instance was affected if it was publicly accessible with Laravel APP_DEBUG=true and APP_ENV=local, and an unhandled exception could return debug output containing environment variables. The issue was fixed on or before 2026-09-02.