CVE-2026-27894 | LDAPAccountManager lam up to 9.4 config filename control (GHSA-88hf-2cjm-m9g8)
A vulnerability classified as critical was found in LDAPAccountManager lam up to 9.4. Impacted is an unknown function in the library /var/lib/ldap-account-manager/config. Executing a manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is registered as CVE-2026-27894. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.