← all CVEs

CVE-2026-94535

lamp-cloud through 5.10.0 Unauthorized Notification Deletion

Published 21 Sep 2026Updated 21 Sep 2026

Severity: HIGH

7.1

CVSS Base Score

Description

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to permanently remove notifications belonging to other users without recipient validation.

Affected products (1)

  • dromara lamp-cloud

Problem types

  • CWE-639 Authorization Bypass Through User-Controlled Key

Get alerted the moment a CVE like this matches your stack.

Create a free account