


Perceptive Security
SOC/SIEM Consultancy

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local …
Published:
17 maart 2026 om 23:00:00
Alert date:
18 maart 2026 om 01:01:39
Source:
nvd.nist.gov
Identity & Access, Web Technologies
LDAP Account Manager (LAM) versions prior to 9.5 contain a local file inclusion vulnerability in the PDF export functionality that allows authenticated users to include local PHP files and execute code. When combined with GHSA-88hf-2cjm-m9g8, this enables arbitrary code execution. The vulnerability requires user authentication to exploit. Version 9.5 addresses this issue, and workarounds include making the config directory read-only and removing PDF profile files.
Technical details
Mitigation steps:
Affected products:
LDAP Account Manager (LAM)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27894
https://github.com/LDAPAccountManager/lam/releases/tag/9.5
https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-88hf-2cjm-m9g8
https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-w7xq-vjr3-p9cf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
