CVE-2026-91996High· 7.5▾ MidnightPoC availablelamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getPrope…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Exploit / PoC code exists
lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information including JVM classpath, filesystem paths, operating system details, and startup secrets.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94536Medium· 4.3lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource
CVE-2026-94532Medium· 6.5lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById
CVE-2026-94535High· 7.1lamp-cloud through 5.10.0 Unauthorized Notification Deletion
CVE-2026-94534High· 7.1lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints
CVE-2026-94533Medium· 6.5lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file
CVE-2026-92992Medium· 6.3A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5