Junglewise Threat Intelligence

CVE-2026-94533: lamp-cloud authorization bypass in FileAnyoneController

CVE-2026-94533 · Severity: medium · CVSS 6.5 · Published 2026-09-21

Technologies: Dromara Lamp-Cloud. Vendors: Dromara.

Executive brief

lamp-cloud is a cloud-based development platform used for multi-tenant microservices. An authorization bypass in the file download functionality allows any authenticated user to download files belonging to other users by guessing or obtaining valid file identifiers, potentially exposing sensitive documents and data.

Technical details

The FileAnyoneController endpoints /anyone/file/down and /anyone/file/download lack ownership validation. They retrieve files by ID only without checking the created_by column against the requesting user, allowing Broken Object Level Access (BOLA). Requires authentication but no additional preconditions; an attacker can iterate file IDs to access arbitrary files.

Affected products

  • Dromara lamp-cloud through 5.10.0

Timeline

  • 2026-09-21: disclosed

References

Related threats