Remote Code Execution Vulnerability in Dromara Lamp-Cloud
CVE-2026-9498
Key Information:
- Vendor
Dromara
- Status
- Vendor
- CVE Published:
- 25 May 2026
Badges
What is CVE-2026-9498?
A vulnerability exists in the Dromara lamp-cloud up to version 5.6.2, where the GroovyClassLoader.parseClass function is susceptible to manipulation through the DefMsgTemplate.content argument. This leads to improper neutralization of special elements used within the template engine, enabling a potential attacker to execute arbitrary code remotely. The flaw has been publicly disclosed, raising concerns for users as the vendor has not issued a corresponding response.
Affected Version(s)
lamp-cloud 5.6.0
lamp-cloud 5.6.1
lamp-cloud 5.6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
