{ "document": { "category": "csaf_vex", "csaf_version": "2.0", "lang": "en-US", "publisher": { "category": "coordinator", "contact_details": "https://www.cisa.gov/report", "issuing_authority": "CISA", "name": "CISA", "namespace": "https://www.cisa.gov/" }, "title": "Cadmos LTI", "tracking": { "current_release_date": "2026-10-01T18:50:47Z", "generator": { "engine": { "name": "VINCE-NT", "version": "1.15.0+build.129" } }, "id": "VA-26-275-05", "initial_release_date": "2026-10-01T18:50:47Z", "status": "final", "version": "1.0.0", "revision_history": [ { "number": "1.0.0", "summary": "Initial publication", "date": "2026-10-01T18:50:47Z" } ] }, "distribution": { "tlp": { "label": "WHITE" } }, "notes": [ { "text": "All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\\"as is\\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).", "title": "Legal Notice", "category": "legal_disclaimer" }, { "text": "Worldwide", "title": "Countries and Areas Deployed", "category": "other" }, { "text": "Information Technology", "title": "Critical Infrastructure Sectors", "category": "other" }, { "text": "The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext.", "title": "Risk Evaluation", "category": "summary" }, { "text": "Fixed on or before 2026-09-02.", "title": "Recommended Practices", "category": "general" }, { "text": "United States", "title": "Company Headquarters Location", "category": "other" } ], "references": [ { "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/VA-26-275-05.json", "summary": "Vulnerability Advisory VA-26-275-05 CSAF", "category": "self" } ] }, "product_tree": { "branches": [ { "category": "vendor", "name": "Eummena", "branches": [ { "category": "product_name", "name": "Cadmos LTI", "branches": [ { "category": "product_version_range", "name": "<2026-09-02", "product": { "name": "Eummena Cadmos LTI <2026-09-02", "product_id": "CSAFPID-0001" } }, { "category": "product_version", "name": "2026-09-02", "product": { "name": "Eummena Cadmos LTI 2026-09-02", "product_id": "CSAFPID-0002" } } ] } ] } ] }, "vulnerabilities": [ { "cve": "CVE-2026-102628", "cwe": { "id": "CWE-215", "name": "Insertion of Sensitive Information Into Debugging Code" }, "notes": [ { "category": "summary", "text": "The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.", "title": "Description" }, { "category": "details", "title": "SSVC", "text": "SSVCv2/E:N/A:Y/T:P/2026-09-29T15:07:36Z/" } ], "title": "Cadmos LTI exposure of sensitive information via debug mode", "product_status": { "known_affected": [ "CSAFPID-0001" ], "fixed": [ "CSAFPID-0002" ] }, "references": [ { "category": "external", "summary": "raw.githubusercontent.com", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/VA-26-275-05.json" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-102628" } ], "scores": [ { "cvss_v3": { "baseScore": 9.3, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N", "version": "3.1" }, "products": [ "CSAFPID-0001" ] } ], "remediations": [ { "category": "mitigation", "details": "No longer accessible as of 2026-09-02.", "product_ids": [ "CSAFPID-0001" ], "date": "2026-09-02T00:00:00Z" }, { "category": "mitigation", "details": "No longer accessible as of 2026-09-02.", "product_ids": [ "CSAFPID-0002" ], "date": "2026-09-02T00:00:00Z" } ], "acknowledgments": [ { "names": [ "Dibyataru Chakraborty (Xhunter)" ] } ], "release_date": "2026-10-01T00:00:00Z" } ] }