{"id":"CVE-2026-94532","published":"2026-09-21T22:17:00.010","lastModified":"2026-09-21T22:17:00.010","description":"lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensitive user information including mobile numbers, email addresses, national identity card numbers, and WeChat and DingTalk OpenIDs.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/lamp/poc-01-anyone-userinfo-bola.py","tags":[]},{"url":"https://github.com/dromara/lamp-cloud","tags":[]},{"url":"https://github.com/dromara/lamp-cloud/blob/bdc1a406eb0f6291e9f6dbad9cbccd67bc6a37b6/lamp-oauth/lamp-oauth-controller/src/main/java/top/tangyh/lamp/oauth/controller/UserInfoController.java#L55-L61","tags":[]},{"url":"https://www.vulncheck.com/advisories/lamp-cloud-through-5.10.0-unauthorized-user-profile-access-via-getuserinfobyid","tags":[]}],"exploitRefs":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/lamp/poc-01-anyone-userinfo-bola.py","tags":[]},{"url":"https://github.com/dromara/lamp-cloud","tags":[]},{"url":"https://github.com/dromara/lamp-cloud/blob/bdc1a406eb0f6291e9f6dbad9cbccd67bc6a37b6/lamp-oauth/lamp-oauth-controller/src/main/java/top/tangyh/lamp/oauth/controller/UserInfoController.java#L55-L61","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows authenticated users to read other users' full profiles, including sensitive information like mobile numbers and national identity card numbers.","exploitability":"Exploitation requires authentication but is relatively straightforward due to the ability to iterate through userId parameters.","blast_radius":"If exploited, it could lead to significant data breaches affecting multiple users’ private information.","remediation":"Update to the latest version of lamp-cloud (5.10.1 or later) which includes a fix for this vulnerability.","tags":["auth-bypass","web","info-leak","sensitive-data"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:21:01.891Z"}}