Junglewise Threat Intelligence

CVE-2026-94535: lamp-cloud authorization bypass in deleteMyNotice

CVE-2026-94535 · Severity: high · CVSS 7.1 · Published 2026-09-21

Technologies: Dromara Lamp-Cloud. Vendors: Dromara.

Executive brief

lamp-cloud is a microservice platform framework for building back-office applications. An authenticated user can delete notifications belonging to other users by exploiting missing ownership checks in the deleteMyNotice endpoint, permanently removing messages without the recipient's knowledge or consent. This allows any authenticated user to disrupt communication for other users in the system.

Technical details

The deleteMyNotice endpoint in ExtendNoticeController fails to validate that the authenticated user is the recipient of the notices before deletion. A sibling method (mark) correctly filters by employeeId/recipientId, but deleteMyNotice passes user-supplied notice IDs directly to removeByIds() without ownership verification. Authenticated network access is required; the vulnerability allows horizontal privilege escalation to delete arbitrary users' notifications via DELETE /anyone/extendNotice/deleteMyNotice.

Affected products

  • dromara lamp-cloud through 5.10.0

Timeline

  • 2026-09-21: disclosed

References

Related threats