Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.CreditsLaban Sköllermark at Reversec Sweden ABReferenceshttps://labs.reversec.com/advisories/2026/03/long-session-lifetime-in-truesec-lapswebui