๐Ÿ” CVE Alert

CVE-2026-102628

CRITICAL 9.3

Cadmos LTI exposure of sensitive information via debug mode

CVSS Score
9.3
EPSS Score
0.0%
EPSS Percentile
0th

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.

CWE CWE-215 CWE-489
Vendor eummena
Product cadmos lti
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for eummena cadmos lti

Be the first to know when new critical vulnerabilities affecting eummena cadmos lti are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

Eummena / Cadmos LTI
0 < *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
raw.githubusercontent.com: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/VA-26-275-05.json cve.org: https://www.cve.org/CVERecord?id=CVE-2026-102628

Credits

Dibyataru Chakraborty (Xhunter)