← Back to search

CVE-2026-94534

7.1 HIGHpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows authenticated attackers to modify any user's profile fields, including nicknames and avatars, by exploiting PUT requests to specific endpoints.
Exploitability
Exploitation requires authentication but no complex setup; attackers need access to target user IDs in request bodies.
Blast radius
If exploited, this vulnerability could lead to significant data breaches affecting multiple users' private information.
Prioritized remediation
Update to the latest version of lamp-cloud (5.10.1 or later) which addresses this issue.
auth-bypasswebprofile-modificationpatch-available

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodies to rewrite profile fields including nickname, ID card, sex, nation, education, work description, and avatar attachments of other users.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Weaknesses

CWE-639

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.