Description
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.
Published: 2026-10-01
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

The Cadmos LTI application at cadmos.eummena.io was running with Laravel’s debug mode enabled, exposing the entire server environment when an unhandled exception occurred. An unauthenticated attacker could send a simple GET request to any exposed endpoint, triggering the exception and receiving plaintext data including all .env configuration variables. This vulnerability allows attackers to obtain credentials, secret keys, and other sensitive data, resulting in a high‑severity confidentiality breach. The issue is formally classified as CWE-215 (Information Exposure Through Insecure Disclosure) and CWE-489 (Exposure of Sensitive Data Through Exception Handling).

Affected Systems

Eummena’s Cadmos LTI product, a Laravel framework application hosted publicly at cadmos.eummena.io, was affected. No specific application version is listed, so all instances of Cadmos LTI that were running with debug mode enabled in a publicly accessible environment are considered vulnerable.

Risk and Exploitability

The CVSS score of 9.2 places this flaw in the Critical range, indicating that exploitation offers significant impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because the application was publicly reachable and the vulnerability does not require any authentication or prior access, the likelihood of exploitation is high. An attacker can simply craft a web request to trigger the exception and harvest sensitive environment variables without any additional technical barriers.

Generated by OpenCVE AI on October 1, 2026 at 21:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the vendor‑provided fix released before 2026-09-02 that disables Laravel debug mode in the production environment.
  • Set the APP_DEBUG environment variable to false and ensure APP_ENV is set to production or staging for all live instances so that exceptions do not leak environment information.
  • Validate the fix by triggering a controlled exception in a non‑prod environment and confirming that no .env or sensitive data is returned to the client.

Generated by OpenCVE AI on October 1, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.
Title Cadmos LTI exposure of sensitive information via debug mode
Weaknesses CWE-215
CWE-489
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T19:44:40.666Z

Reserved: 2026-09-29T15:06:59.315Z

Link: CVE-2026-102628

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:21.447

Modified: 2026-10-01T20:37:52.400

Link: CVE-2026-102628

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:30:13Z

Weaknesses
  • CWE-215

    Insertion of Sensitive Information Into Debugging Code

  • CWE-489

    Active Debug Code