CVE-2026-27894: LAM has Authenticated Local File Inclusion (LFI) in PDF export
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in the PDF export that allows users to include local PHP files and this way execute code. In combination with GHSA-88hf-2cjm-m9g8 this allows to execute arbitrary code. Users need to login to LAM to exploit this vulnerability. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user and delete the PDF profile files (making PDF exports impossible).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27894?
CVE-2026-27894 has a medium severity level due to its potential for local file inclusion vulnerabilities.
How do I fix CVE-2026-27894?
To fix CVE-2026-27894, upgrade the LDAP Account Manager to version 9.5 or later.
What kind of vulnerability is CVE-2026-27894?
CVE-2026-27894 is an Authenticated Local File Inclusion (LFI) vulnerability.
What can attackers do with CVE-2026-27894?
Attackers exploiting CVE-2026-27894 can potentially include local files which may lead to the exposure of sensitive information.
Which versions of LDAP Account Manager are affected by CVE-2026-27894?
LDAP Account Manager versions prior to 9.5 are affected by CVE-2026-27894.