CVE-2026-91996
lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information including JVM classpath, filesystem paths, operating system details, and startup secrets.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.36%
- CWE
- CWE-306
- Published
- 2026-09-15
- Last modified
- 2026-09-17
Affected products
- dromara lamp-cloud
Weakness type
Related vulnerabilities
- CVE-2026-67277 — Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
- CVE-2026-81735 — UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Execution
- CVE-2026-65956 — KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF
- CVE-2026-92808 — Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise
- CVE-2026-82695 — Tenda AC18 Telnet telnet missing authentication
- CVE-2026-82694 — Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication
- CVE-2026-82693 — Tenda AC1206 Web UI telnet TendaTelnet missing authentication
- CVE-2026-80462 — Privilege Escalation in Progress Chef Automate