CVE-2026-5529 | Dromara lamp-cloud up to 5.8.1 DefUserController /defUser/pageUser improper authorization (Issue 403)
A vulnerability has been found in Dromara lamp-cloud up to 5.8.1 and classified as critical. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorization.
This vulnerability is identified as CVE-2026-5529. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.