Sceawere
Vulnerability Detail
CVE-2026-102628UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Laravel Debug Mode Information Disclosure
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 1d ago
- Vendor
- Eummena
- Product
- Cadmos LTI
- Attack Type
- CWE-215 Insertion of Sensitive Information Into Debugging Code
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-10-01T20:17:21.447Z",
"pubdate": "2026-10-01T20:17:21.447Z",
"executiveSummary": "The Cadmos LTI application, hosted at cadmos.eummena.io, was found to have Laravel debug mode enabled in a production-like environment. This configuration error represents an information disclosure vulnerability categorized as improper neutralization of sensitive information. By triggering an unhandled exception via a crafted GET request, an unauthenticated attacker could cause the application to dump the full stack trace and internal server environment variables to the HTTP response.\nThe primary risk implication is the exposure of critical configuration parameters, including plaintext credentials, database connection strings, API keys, and secret tokens defined within the .env file. This facilitates a complete compromise of the underlying application infrastructure. The vulnerability does not require authentication or elevated privileges, as the exposure occurs during the standard error handling process of the Laravel framework when APP_DEBUG is set to true. Remediation involves strictly enforcing environment-specific configurations to ensure that debug information is never exposed in publicly accessible instances.",
"technicalDetails": "The vulnerability resides in the misconfiguration of the Laravel framework's runtime environment, specifically the activation of 'debug mode'. When the APP_DEBUG variable is set to true within the .env file, the framework utilizes the 'Whoops' error handler or the native Laravel Ignition/Error page suite to provide detailed diagnostic information to the end-user during application failure.\nThe root cause is the failure to distinguish between development and production environment configurations. In a development context, this behavior is intended to assist developers in identifying bugs; however, in a public-facing instance, it serves as an oracle for internal system architecture. The attack flow initiates when an unauthenticated attacker sends a malformed or intentionally erroneous GET request to the application, such as requesting a non-existent route or providing invalid parameter types that force the application logic into an unhandled exception state.\nUpon encountering the exception, the Laravel framework catches the error and generates an interactive error page. This page contains a significant amount of sensitive metadata, including the full file path of the application, the local filesystem structure, active environment variables, and the contents of the .env file. Because the application was accessible over the network without authentication, the attacker can capture the HTTP response and parse the HTML to extract plaintext credentials for database backends, third-party services, and session drivers.\nThe impact of this exploit is severe, as it bypasses application-level security controls entirely. Once an attacker obtains the application key (APP_KEY), they may be able to forge session cookies, conduct remote code execution (RCE) via serialized objects (if applicable to the specific version of Laravel's deserialization logic), or access external resources managed by the credentials stored in the .env file. There is no requirement for specific network positioning other than the ability to reach the web server via the HTTP/HTTPS protocol. The vulnerability remains critical due to the ease of exploitation, as it requires no specialized payloads or post-exploitation scripts beyond standard web traffic, allowing an attacker to map the internal server state and facilitate further lateral movement within the infrastructure."
}