← Back

Lapswebui

lapswebui

Vendor: Truesec • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Truesec
1Lapswebui
Jun 17, 2026
Mar 16, 2026
6.0 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.
1Truesec
1Lapswebui
Jun 17, 2026
Mar 16, 2026
6.0 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.
1Truesec
1Lapswebui
Jun 17, 2026
Mar 16, 2026
6.0 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.