Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02. | |
| Title | Cadmos LTI exposure of sensitive information via debug mode | |
| Weaknesses | CWE-215 CWE-489 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-01T19:44:40.666Z
Reserved: 2026-09-29T15:06:59.315Z
Link: CVE-2026-102628
No data.
Status : Deferred
Published: 2026-10-01T20:17:21.447
Modified: 2026-10-01T20:37:52.400
Link: CVE-2026-102628
No data.
OpenCVE Enrichment
No data.