Authorization Bypass in Lamp-Cloud by Dromara
CVE-2026-94532
Key Information:
- Vendor
Dromara
- Status
- Vendor
- CVE Published:
- 21 September 2026
Badges
What is CVE-2026-94532?
Lamp-Cloud, up to version 5.10.0, has a vulnerability in the getUserInfoById endpoint which allows authenticated users to bypass authorization checks. This flaw enables individuals to access full profiles of any user within the system by manipulating the userId parameter. As a consequence, attackers can potentially harvest sensitive information, including mobile numbers, email addresses, national ID card numbers, and social media identifiers such as WeChat and DingTalk OpenIDs.
Affected Version(s)
lamp-cloud 0 <= 5.10.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
