Unrated severityNVD Advisory· Published Mar 17, 2026· Updated Mar 18, 2026
LAM has incorrect regular expression in PDF export component that allows user to upload files of any type
CVE-2026-27895
Description
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.
Affected products
1- Range: < 9.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/LDAPAccountManager/lam/releases/tag/9.5mitrex_refsource_MISC
- github.com/LDAPAccountManager/lam/security/advisories/GHSA-88hf-2cjm-m9g8mitrex_refsource_CONFIRM
- github.com/LDAPAccountManager/lam/security/advisories/GHSA-w7xq-vjr3-p9cfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.