CVE-2026-5529

MEDIUM

Dromara lamp-cloud DefUserController pageUser improper authorization

Title source: cna
STIX 2.1

Description

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-355282 | Dromara lamp-cloud DefUserController pageUser improper authorization
https://vuldb.com/vuln/355282
Signature, Permissions Required signature permissions-required
VDB-355282 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/355282/cti
Third Party Advisory third-party-advisory
Submit #782103 | Dromara lamp-cloud 5.8.1 Broken object property level authorization
https://vuldb.com/submit/782103
Exploit exploit issue-tracking
https://github.com/dromara/lamp-cloud/issues/403

Scores

CVSS v3 4.3
EPSS 0.0027
EPSS Percentile 18.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (2)
Dromara/lamp-cloud 5.8.0
Dromara/lamp-cloud 5.8.1
Published Apr 05, 2026
Tracked Since Apr 05, 2026