CVE-2026-5529 describes an improper authorization vulnerability in the `pageUser` function of Dromara lamp-cloud's DefUserController, affecting versions up to 5.8.1. Rated Medium (CVSS 4.3), this flaw allows a remote attacker with low privileges to achieve low confidentiality impact due to its low attack complexity and lack of user interaction. Although not currently in CISA's KEV catalog, an exploit for this vulnerability is publicly available and may be used. The project was informed but has not yet responded to the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Dromara | Lamp-Cloud | 5.8.0, 5.8.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.