{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lamp-cloud--5.10.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lamp_cloud:lamp_cloud:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-91996"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lamp-cloud (\u003c= 5.10.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authentication-bypass","information-disclosure"],"_cs_type":"advisory","_cs_vendors":["lamp-cloud"],"content_html":"\u003cp\u003eCVE-2026-91996 is an authentication bypass vulnerability affecting lamp-cloud versions up to and including 5.10.0. The vulnerability originates from an overly permissive whitelist configuration that allows unauthenticated access to the path pattern /*/anno/**. Defenders should be aware that this configuration enables remote, unauthenticated actors to access sensitive internal endpoints without valid session credentials.\u003c/p\u003e\n\u003cp\u003eThe most critical impact of this vulnerability is the potential for information disclosure via the /defGenProject/anno/getProperties endpoint. By sending a crafted POST request to this endpoint, an attacker can extract the server's full JVM system property map. This data contains sensitive environment information including the full JVM classpath, absolute filesystem paths, operating system metadata, and internal startup configuration secrets. This exposure provides significant reconnaissance value to an attacker, potentially facilitating further exploitation of the underlying host or the application infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to conduct reconnaissance and gain access to sensitive server-side configuration secrets. The disclosed JVM properties often include internal paths, service secrets, and deployment details that assist in lateral movement or subsequent privilege escalation attempts against the host environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade lamp-cloud to a patched version beyond 5.10.0 immediately to remove the insecure authentication bypass.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests targeting the /anno/ URI pattern, specifically the /defGenProject/anno/getProperties endpoint.\u003c/li\u003e\n\u003cli\u003eAudit custom authentication filters and path whitelists to ensure no sensitive internal management endpoints are reachable without authorization.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T13:40:52Z","date_published":"2026-09-15T13:40:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lamp-cloud-auth-bypass/","summary":"An authentication bypass vulnerability in lamp-cloud versions 5.10.0 and earlier allows unauthenticated attackers to exfiltrate sensitive JVM system properties via insecurely whitelisted API endpoints.","title":"Unauthenticated Information Disclosure in lamp-cloud via CVE-2026-91996","url":"https://feed.craftedsignal.io/briefs/2026-09-lamp-cloud-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Lamp-Cloud (\u003c= 5.10.0)","version":"https://jsonfeed.org/version/1.1"}