---
id: CVE-2026-94532
title: >-
  lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in
  the getUserInfoById endpoint that allows authenticated users to read any other
  user's full profile
summary: >-
  lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in
  the getUserInfoById endpoint that allows authenticated users to read any other
  user's full profile. Attackers can iterate the userId parameter to harvest
  sensiti…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: dromara
product: lamp-cloud
affected:
  - lamp-cloud <= 5.10.0
published: '2026-09-21'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T23:19:22.413'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94532'
references:
  - url: >-
      https://github.com/LinYuanyi1/cve-request-poc/blob/master/lamp/poc-01-anyone-userinfo-bola.py
    label: disclosure@vulncheck.com
  - url: 'https://github.com/dromara/lamp-cloud'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/dromara/lamp-cloud/blob/bdc1a406eb0f6291e9f6dbad9cbccd67bc6a37b6/lamp-oauth/lamp-oauth-controller/src/main/java/top/tangyh/lamp/oauth/controller/UserInfoController.java#L55-L61
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/lamp-cloud-through-5.10.0-unauthorized-user-profile-access-via-getuserinfobyid
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T22:50:24.259640Z'
epss: 0.00436
epssPercentile: 0.35164
ingestedAt: '2026-09-21T21:53:57.428Z'
---

## Overview

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensitive user information including mobile numbers, email addresses, national identity card numbers, and WeChat and DingTalk OpenIDs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
