CVE-2026-27894Disclosure(ldap-account-manager / ldap_account_manager)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch ldap-account-manager ldap_account_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in the PDF export that allows users to include local PHP files and this way execute code. In combination with GHSA-88hf-2cjm-m9g8 this allows to execute arbitrary code. Users need to login to LAM to exploit this vulnerability. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user and delete the PDF profile files (making PDF exports impossible).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ldap_account_manager

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-18); latest day: 2
  • 7 total mentions across 2 days

Affected systems

Products
ldap_account_manager

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-03-18: 5Mentions · 2026-03-19: 2Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 4Technical Details · 2026-03-19: 103-1803-19
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-185
Disclosure3General1Patch1
2026-03-192
Disclosure1General1
Full discourse7 posts
  • ɐʞsǝs@akses_0x00
    General

    @Deathlurk @IceSolst this one? https://www.cvedetails.com/cve/CVE-2026-27894/ yeh also wild

    Post summary

    The tweet simply points to the CVE entry for CVE‑2026‑27894 with no additional details about the vulnerability, exploitability, or remediation.

    2000044
    281 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-27894 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27894 #CVE-2026-27894 #CVE #High  #CyberSecurity #InfoSec https://t.co/hcrHWly3tZ

    Post summary

    The tweet announces CVE-2026-27894 with a severity score of 8.8, affecting multiple unspecified products, but offers no details about exploitation or fixes.

    0000044
    104 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-27894 - High LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in ... https://www.thehackerwire.com/vulnerability/CVE-2026-27894/ https://t.co/A57tosHl2c

    Post summary

    CVE-2026-27894 is a local file inclusion vulnerability affecting LDAP Account Manager versions before 9.5, with no PoC, exploit, or patch information disclosed in the provided text.

    0000035
    138 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27894 Local File Inclusion in LDAP Account Manager Prior to Version 9.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27894

    Post summary

    The text announces CVE-2026-27894, a local file inclusion flaw in LDAP Account Manager versions before 9.5, with a reference to a vulnerability details page, but provides no PoC, exploit, or patch information.

    0000041
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27894 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file i… https://www.cve.org/CVERecord?id=CVE-2026-27894

    Post summary

    The post notes CVE-2026-27894 as a local file inclusion issue in LDAP Account Manager before version 9.5 but does not provide further technical detail, PoC, exploit, or patch information.

    00000113
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-27894 - LAM has Authenticated Local File Inclusion (LFI) in PDF export Intel Report: https://ift.tt/ejPwMlN

    Post summary

    The message alerts about CVE-2026-27894, an authenticated LFI flaw in LAM’s PDF export, without indicating any PoC, exploit, active use, or patch.

    0000040
    335 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27894: HIGH] LDAP Account Manager (LAM) webfrontend had a local file inclusion vulnerability pre-version 9.5 allowing code execution. Upgrade to v9.5 or make config files read-only for fix.#cve,CVE-2026-27894,#cybersecurity https://cvefind.com/CVE-2026-27894

    Post summary

    The post identifies a CVE‑2026‑27894 LFI vulnerability in LDAP Account Manager before v9.5 and recommends upgrading to v9.5 or making configuration files read‑only as a fix.

    0000082
    603 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appldap-account-managerldap_account_manager---

Explore more