CVE-2026-69100
HIGHLAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution
Title source: cnaDescription
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.
References (3)
Core 3
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/dromara/lamp-cloud/issues/408
Patch patch
Patch Commit
https://github.com/dromara/lamp-cloud/commit/84b0c27d3693e468c2c690d9fbc8ea9c22cd34e3
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/lamp-gluefactory-unsandboxed-groovy-script-remote-code-execution
Scores
CVSS v3
8.8
EPSS
0.0055
EPSS Percentile
43.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (2)
dromara/lamp-cloud
< 5.6.2
dromara/lamp-cloud
84b0c27d3693e468c2c690d9fbc8ea9c22cd34e3
Published
Aug 04, 2026
Tracked Since
Aug 04, 2026