---
id: CVE-2026-102628
title: >-
  The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode
  enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment
summary: >-
  The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode
  enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment.
  An unauthenticated attacker could send a GET request and trigger an unhandled
  exc…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-215
  - CWE-489
vendor: Eummena
product: Cadmos LTI
affected:
  - cadmos_lti < *
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T20:37:52.400'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102628'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/VA-26-275-05.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-102628'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T19:58:57.560Z'
---

## Overview

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
