PT-2026-30389 · Unknown · Dromara Lamp-Cloud

Aibot88

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5529

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dromara lamp-cloud versions up to 5.8.1
Description A flaw exists in the pageUser function within the /defUser/pageUser file of the DefUserController component, leading to improper authorization. This issue is remotely exploitable. The exploit is publicly available.
Recommendations For versions up to 5.8.1, address the improper authorization in the pageUser function of the /defUser/pageUser file within the DefUserController component.

Exploit

Fix

Incorrect Privilege Assignment

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-5529

Affected Products

Dromara Lamp-Cloud