What is CVE-2026-19758?
This CVE describes a path traversal vulnerability in dromara lamp-cloud up to version 5.10.0, affecting the chunk-check endpoint in FileChunkController.java. Remote attackers can exploit this by manipulating the argument to gain unauthorized access to files on the server. Users should update to the latest version and monitor for suspicious requests.
Azərbaycanca: Bu CVE, dromara lamp-cloud proqramında 5.10.0 versiyasına qədər mövcud olan path traversal zəifliyini təsvir edir. Zəiflik FileChunkController.java faylındakı chunk-check endpoint-də argument ilə manipulyasiya nəticəsində yaranır, uzaqdan hücum edən şəxsə serverdəki fayllara icazəsiz giriş imkanı verə bilər. Sistem sahibləri lamp-cloud platformasını ən son versiyaya yeniləməli və şübhəli sorğulara qarşı monitorinq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: dromara
FAQ2
Which component of lamp-cloud is affected by CVE-2026-19758?
The vulnerability affects the chunk-check endpoint in the FileChunkController.java file.
What can a remote attacker gain by exploiting this vulnerability?
Unauthorized access to files on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.