Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-102628
Eummena Cadmos LTI — Cadmos LTI exposure of sensitive information via debug mode
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H N N 9.2 .0034 24.8 —
AFFECTED
Product Versions Fixed
Cadmos LTI unspecified 2026-09-02
TIMELINE
Sep 29 Reserved by cisa-cg
Oct 1 Published (CNA: cisa-cg)
Oct 5 PATCH SHIPPED — CVE-2026-102628 (Eummena Cadmos LTI). Fixed in Cadmos LTI 2026-09-02.
Description
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 29, 2026 | Reserved | Reserved by cisa-cg |
| October 1, 2026 | Published | Published (CNA: cisa-cg) |
| October 5, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-102628 (Eummena Cadmos LTI). Fixed in Cadmos LTI 2026-09-02. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Eummena | Cadmos LTI | — | — | 2026-09-02 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-102628 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.