CVE-2026-5529Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-05: 4Technical Details · 2026-04-05: 204-05
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5529 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5529 #CVE-2026-5529 #CVE #Medium #CyberSecurity #InfoSec https://t.co/e4E5z9QmyN

    Post summary

    The tweet provides a brief alert for CVE‑2026‑5529 with severity and affected scope, but offers no technical details, exploit code, or patch information.

    0000028
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5529 A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserC… https://www.cve.org/CVERecord?id=CVE-2026-5529 ----- Traducción: CVE-2026-5529 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-5529, detailing its impact on Dromara lamp-cloud up to version 5.8.1, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000035
    63 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5529 A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserC… https://www.cve.org/CVERecord?id=CVE-2026-5529

    Post summary

    An announcement of CVE-2026-5529 affecting Dromara lamp-cloud up to 5.8.1, with details limited to the impacted function and file path, and no further information on exploitation or mitigation.

    00000520
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5529 - Dromara lamp-cloud DefUserController pageUser improper authorization Intel Report: https://ift.tt/Z54Cxhk

    Post summary

    The alert identifies CVE‑2026‑5529 as an improper authorization flaw in Dromara lamp‑cloud’s DefUserController. No proof‑of‑concept, exploit code, active attack, patch, or debunking information is provided.

    0000040
    281 followersView on X

Explore more