Description
lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information including JVM classpath, filesystem paths, operating system details, and startup secrets.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

lamp‑cloud releases through 5.10.0 expose a /defGenProject/anno/getProperties endpoint that is accessible without authentication. The endpoint returns the full JVM system property map, which includes classpath, filesystem paths, OS details, and startup secrets. This flaw, identified as CWE‑306, allows unauthenticated attackers to read sensitive information from the deployment environment.

Affected Systems

All lamp‑cloud deployments up to and including version 5.10.0 are affected. Any installation that has not applied a newer patch or configuration update is susceptible to this vulnerability.

Risk and Exploitability

With a high CVSS score of 8.7, the risk of exploitation is significant. The EPSS score is below 1%, indicating a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the /defGenProject/anno/getProperties endpoint is publicly reachable without authentication, attackers can reach it remotely via an HTTP POST request, harvest the full JVM property map, and disclose confidential information such as classpath, filesystem paths, operating system details, and startup secrets. The outcome is information disclosure rather than remote code execution or denial of service.

Generated by OpenCVE AI on September 17, 2026 at 17:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑provided patch that secures the /defGenProject/anno/getProperties endpoint or upgrade to a later lamp‑cloud release where authentication is enforced.
  • If a patch is unavailable, configure the web application’s security settings to restrict access to the /defGenProject/anno/getProperties endpoint entirely from the deployment.
  • Use network isolation or a reverse‑proxy firewall rule to limit external access to the lamp‑cloud service, ensuring that only trusted IP ranges can reach the JVM properties endpoint.
  • Implement regular vulnerability scanning and monitoring to detect unauthorized attempts to access the endpoint and alert security teams promptly.

Generated by OpenCVE AI on September 17, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Dromara
Dromara lamp-cloud
Vendors & Products Dromara
Dromara lamp-cloud

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information including JVM classpath, filesystem paths, operating system details, and startup secrets.
Title lamp-cloud through 5.10.0 Missing Authentication for JVM Properties Endpoint
First Time appeared Tangyh
Tangyh lamp-cloud
Weaknesses CWE-306
CPEs cpe:2.3:a:tangyh:lamp-cloud:*:*:*:*:*:*:*:*
Vendors & Products Tangyh
Tangyh lamp-cloud
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dromara Lamp-cloud
Tangyh Lamp-cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:35.694Z

Reserved: 2026-09-15T11:11:13.312Z

Link: CVE-2026-91996

cve-icon Vulnrichment

Updated: 2026-09-17T14:23:25.426Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T12:17:55.093

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-91996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function