CVE-2026-69100

HIGH

LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution

Title source: cna
STIX 2.1

Description

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.

Scores

CVSS v3 8.8
EPSS 0.0055
EPSS Percentile 43.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
dromara/lamp-cloud < 5.6.2
dromara/lamp-cloud 84b0c27d3693e468c2c690d9fbc8ea9c22cd34e3
Published Aug 04, 2026
Tracked Since Aug 04, 2026