What is CVE-2026-19757?
CVE-2026-19757 is a path traversal vulnerability found in Dromara lamp-cloud up to version 5.10.0, specifically in the FileAnyoneController.java component. This allows remote attackers to manipulate the bucket/bizType argument to gain unauthorized access to the file system. Users are advised to upgrade to the latest version immediately.
Azərbaycanca: CVE-2026-19757, Dromara lamp-cloud platformasının 5.10.0 versiyasına qədər olan versiyalarında FileAnyoneController.java faylında aşkarlanan path traversal zəifliyidir. Bu zəiflik uzaqdan təcavüzkara bucket/bizType parametrini manipulyasiya edərək fayl sisteminə icazəsiz giriş imkanı yaradır. İstifadəçilərə dərhal platformanı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: dromara
FAQ2
Which versions of Dromara lamp-cloud are affected by CVE-2026-19757?
This path traversal vulnerability affects Dromara lamp-cloud versions up to 5.10.0.
Which parameter can a remote attacker manipulate in CVE-2026-19757 to gain unauthorized file system access?
A remote attacker can manipulate the bucket/bizType argument in the FileAnyoneController.java component to gain unauthorized access to the file system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.