Ghostwire

CVE-2026-94532: lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows...

HIGH CVSS 6.5 EPSS 0.25% Exploit Available 1 PoC

Published: September 21, 2026 | Last Modified: September 21, 2026

Description

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensitive user information including mobile numbers, email addresses, national identity card numbers, and WeChat and DingTalk OpenIDs.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.25% (17th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Proof-of-Concept Exploits (1)

Security Coverage (1 articles)

References