CVE-2026-94533 | dromara lamp-cloud up to 5.10.0 Download Endpoint /anyone/file/down FileAnyoneController attachment identifiers authorization

SecurityVulns

A vulnerability, which was classified as problematic, has been found in dromara lamp-cloud up to 5.10.0. This affects the function FileAnyoneController of the file /anyone/file/down of the component Download Endpoint. The manipulation of the argument attachment identifiers leads to authorization bypass.

This vulnerability is documented as CVE-2026-94533. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More