Unrestricted Access Vulnerability in Cadmos LTI Application
CVE-2026-102628
9.2CRITICAL
What is CVE-2026-102628?
The Cadmos LTI application hosted at cadmos.eummena.io was found to have Laravel's debug mode enabled, which allows unauthenticated users to send a GET request that can trigger an unhandled exception. This vulnerability can lead to the exposure of the entire server environment, including sensitive .env configuration variables, revealing critical data in plaintext. The issue has been addressed, and users are advised to ensure their applications do not run in debug mode in production environments.
Affected Version(s)
Cadmos LTI 0
