OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102628

CRITICAL · CVSS 9.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Cadmos LTI application is vulnerable due to Laravel's debug mode being enabled in a publicly accessible environment, allowing unauthenticated attackers to exploit this configuration. This can lead to the exposure of sensitive server environment details, including .env configuration variables, which may contain critical credentials and settings. Organizations using this application should prioritize remediation to mitigate the risk of unauthorized access and data leakage.

CVE
CVE-2026-102628
Severity
CRITICAL
CVSS
9.3
EPSS
0.28%

Original NVD Description

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.