CVE-2026-102628: CWE-215 Insertion of Sensitive Information Into Debugging Code in Eummena Cadmos LTI
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled in a publicly accessible environment, allowing unauthenticated attackers to trigger unhandled exceptions that expose the entire server environment including sensitive .env configuration variables. This vulnerability was fixed on or before 2026-09-02.
AI Analysis
Technical Summary
CVE-2026-102628 describes a vulnerability in the Cadmos LTI application where Laravel's debug mode (APP_DEBUG=true, APP_ENV=local) was enabled in a public environment. An unauthenticated attacker could send a crafted GET request to trigger an unhandled exception, causing Laravel to disclose the full server environment variables in plaintext, including sensitive configuration data from the .env file. This issue is categorized under CWE-215 (Insertion of Sensitive Information Into Debugging Code) and CWE-489 (Exposure of Information Through Debug Information). The vulnerability was addressed with a fix released on or before 2026-09-02.
Potential Impact
The vulnerability allows unauthenticated remote attackers to obtain sensitive server environment information, including all .env configuration variables, which may contain credentials, API keys, and other secrets. This exposure can lead to further compromise of the application and underlying infrastructure. The CVSS v3.1 score is 9.3 (critical), reflecting high confidentiality impact, low attack complexity, no privileges or user interaction required, and scope change.
Mitigation Recommendations
A fix for this vulnerability was released on or before 2026-09-02. It is recommended to ensure Laravel debug mode (APP_DEBUG) is disabled in production environments and to apply the official patch or update provided by the vendor. Since the application is not a cloud service, remediation must be applied by the system administrators. Verify that the environment variables are no longer exposed after applying the fix.
CVE-2026-102628: CWE-215 Insertion of Sensitive Information Into Debugging Code in Eummena Cadmos LTI
Description
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled in a publicly accessible environment, allowing unauthenticated attackers to trigger unhandled exceptions that expose the entire server environment including sensitive .env configuration variables. This vulnerability was fixed on or before 2026-09-02.
CVSS v3.1
Score 9.3critical
Affected software
Eummena
Cadmos LTI
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-102628 describes a vulnerability in the Cadmos LTI application where Laravel's debug mode (APP_DEBUG=true, APP_ENV=local) was enabled in a public environment. An unauthenticated attacker could send a crafted GET request to trigger an unhandled exception, causing Laravel to disclose the full server environment variables in plaintext, including sensitive configuration data from the .env file. This issue is categorized under CWE-215 (Insertion of Sensitive Information Into Debugging Code) and CWE-489 (Exposure of Information Through Debug Information). The vulnerability was addressed with a fix released on or before 2026-09-02.
Potential Impact
The vulnerability allows unauthenticated remote attackers to obtain sensitive server environment information, including all .env configuration variables, which may contain credentials, API keys, and other secrets. This exposure can lead to further compromise of the application and underlying infrastructure. The CVSS v3.1 score is 9.3 (critical), reflecting high confidentiality impact, low attack complexity, no privileges or user interaction required, and scope change.
Mitigation Recommendations
A fix for this vulnerability was released on or before 2026-09-02. It is recommended to ensure Laravel debug mode (APP_DEBUG) is disabled in production environments and to apply the official patch or update provided by the vendor. Since the application is not a cloud service, remediation must be applied by the system administrators. Verify that the environment variables are no longer exposed after applying the fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisa-cg
- Date Reserved
- 2026-09-29T15:06:59.315Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abebc2da43b0b3b89f67a3d
Added to database: 10/01/2026, 20:01:49 UTC
Last enriched: 10/01/2026, 20:16:11 UTC
Last updated: 10/01/2026, 20:16:11 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.