Junglewise Threat Intelligence

CVE-2026-94532: lamp-cloud authorization bypass in getUserInfoById endpoint

CVE-2026-94532 · Severity: medium · CVSS 6.5 · Published 2026-09-21

Technologies: Dromara Lamp-Cloud. Vendors: Dromara.

Executive brief

lamp-cloud is a microservices rapid development platform for enterprise backend systems. An authorization bypass vulnerability in the getUserInfoById endpoint allows authenticated employees to read other employees' sensitive personal information by iterating user IDs, exposing mobile numbers, email addresses, national ID numbers, and linked social media accounts without proper access controls.

Technical details

The getUserInfoById endpoint in UserInfoController accepts a userId parameter with no ownership verification; if userId is null, it defaults to the current user, but when a specific userId is provided, the OauthUserBiz.getUserById() method returns the entire user record including PII fields without checking authorization. The endpoint lives under /anyone/**, which requires only authentication (not specific permissions), allowing any logged-in user to enumerate and harvest full profiles of other users. No user interaction or elevated privileges are required beyond valid credentials.

Affected products

  • dromara lamp-cloud through 5.10.0

Timeline

  • 2026-09-21: disclosed

References

Related threats