lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information including JVM classpath, filesystem paths, operating system details, and startup secrets.
CVE-2026-91996
Score 7.5 from GitHub Security Advisory (severity: HIGH) published 2026-09-15. a secondary CVSS source baseline 7.5; sources differ by 0.0.
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.5
- EG Score
- 7.5(high)
- EG Risk
- 65(Attend)EG Risk 65/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity75% × 45%Exploitation40% × 40%Automatability100% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 0%
- EPSS %ILE
- 30%
- KEV
- Not listed
Published
September 15, 2026
Last Modified
September 17, 2026
Advisory Details (5)
Auto-updated Sep 15, 2026lamp-cloud through 5.10.0 Missing Authentication for JVM Properties Endpoint | Advisories | VulnCheck
https://www.vulncheck.com/advisories/lamp-cloud-through-5.10.0-missing-authentication-for-jvm-properties-endpointGitHub - dromara/lamp-cloud: [灯灯]微服务中后台快速开发平台,支持jdk21、jdk17、jdk8,专注于多租户、开放平台解决方案,亦可作为普通项目(非SaaS架构)的基础开发框架使用,目前已实现插拔式数据库隔离、SCHEMA隔离、字段隔离 等租户隔离方案。 · GitHub
https://github.com/dromara/lamp-cloudlamp-cloud/lamp-generator/lamp-generator-controller/src/main/java/top/tangyh/lamp/generator/controller/DefGenProjectController.java at bdc1a406eb0f6291e9f6dbad9cbccd67bc6a37b6 · dromara/lamp-cloud · GitHub
https://github.com/dromara/lamp-cloud/blob/bdc1a406eb0f6291e9f6dbad9cbccd67bc6a37b6/lamp-generator/lamp-generator-controller/src/main/java/top/tangyh/lamp/generator/controller/DefGenProjectController.java#L61-L64lamp-cloud/lamp-public/lamp-common/src/main/java/top/tangyh/lamp/common/properties/IgnoreProperties.java at bdc1a406eb0f6291e9f6dbad9cbccd67bc6a37b6 · dromara/lamp-cloud · GitHub
https://github.com/dromara/lamp-cloud/blob/bdc1a406eb0f6291e9f6dbad9cbccd67bc6a37b6/lamp-public/lamp-common/src/main/java/top/tangyh/lamp/common/properties/IgnoreProperties.java#L88oss/lamp-cloud.md at main · geo-chen/oss · GitHub
https://github.com/geo-chen/oss/blob/main/lamp-cloud.mdVendor Advisories for CVE-2026-91996(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 28× in last 7d / 28× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-21 04:18 UTCEG score recompute
- 2026-09-21 04:18 UTCGHSA enrichment
- 2026-09-20 20:16 UTCEPSS rescore
- 2026-09-20 16:11 UTCGHSA enrichment
- 2026-09-20 04:04 UTCGHSA enrichment
- 2026-09-19 15:57 UTCEG score recompute
- 2026-09-19 15:57 UTCGHSA enrichment
- 2026-09-19 03:50 UTCEG score recompute
- 2026-09-19 03:50 UTCGHSA enrichment
- 2026-09-18 19:28 UTCEPSS rescore
- 2026-09-18 15:42 UTCGHSA enrichment
- 2026-09-18 03:31 UTCEG score recompute
- 2026-09-18 03:31 UTCGHSA enrichment
- 2026-09-17 19:32 UTCEPSS rescore
- 2026-09-17 15:24 UTCEG score recompute
- 2026-09-17 15:24 UTCGHSA enrichment
- 2026-09-17 14:35 UTCEG score recompute
- 2026-09-17 14:35 UTCGHSA enrichment
- 2026-09-17 13:01 UTCGHSA enrichment
- 2026-09-17 00:54 UTCEG score recompute
- 2026-09-17 00:54 UTCGHSA enrichment
- 2026-09-16 14:09 UTCEPSS rescore
- 2026-09-16 12:47 UTCGHSA enrichment
- 2026-09-16 00:40 UTCEG score recompute
- 2026-09-16 00:40 UTCGHSA enrichment
Show 3 moreShow fewer
- 2026-09-15 12:30 UTCEG score recompute
- 2026-09-15 11:43 UTCEG score recompute
- 2026-09-15 11:42 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Same CWE
10 shownCWE-306
Frequently asked(5)
What is CVE-2026-91996?
When was CVE-2026-91996 disclosed?
Is CVE-2026-91996 actively exploited?
What is the CVSS score of CVE-2026-91996?
How do I remediate CVE-2026-91996?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-91996
Is Your Infrastructure Affected by CVE-2026-91996?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.