CVE-2026-5529: Dromara lamp-cloud DefUserController pageUser improper authorization
A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5529?
CVE-2026-5529 has been classified as a critical severity vulnerability due to its potential for improper authorization.
How do I fix CVE-2026-5529?
To fix CVE-2026-5529, upgrade Dromara lamp-cloud to version 5.8.2 or later, which contains patches for this vulnerability.
What components are affected by CVE-2026-5529?
CVE-2026-5529 affects the DefUserController component, specifically the pageUser function in the /defUser/pageUser file.
Can CVE-2026-5529 lead to data exposure?
Yes, due to the improper authorization, CVE-2026-5529 can potentially allow unauthorized access to sensitive user information.
Which versions of Dromara lamp-cloud are vulnerable to CVE-2026-5529?
Dromara lamp-cloud versions up to and including 5.8.1 are vulnerable to CVE-2026-5529.