Unrestricted Access Vulnerability in Cadmos LTI Application
CVE-2026-102628

9.2CRITICAL

Key Information:

Vendor

Eummena

Vendor
CVE Published:
1 October 2026

What is CVE-2026-102628?

The Cadmos LTI application hosted at cadmos.eummena.io was found to have Laravel's debug mode enabled, which allows unauthenticated users to send a GET request that can trigger an unhandled exception. This vulnerability can lead to the exposure of the entire server environment, including sensitive .env configuration variables, revealing critical data in plaintext. The issue has been addressed, and users are advised to ensure their applications do not run in debug mode in production environments.

Affected Version(s)

Cadmos LTI 0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dibyataru Chakraborty (Xhunter)
.