Vulnerability Description
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/dromara/lamp-cloud/commit/84b0c27d3693e468c2c690d9fbc8ea9c22c
- https://github.com/dromara/lamp-cloud/issues/408
- https://www.vulncheck.com/advisories/lamp-gluefactory-unsandboxed-groovy-script-
FAQ
What is CVE-2026-69100?
CVE-2026-69100 is a vulnerability with a CVSS score of 8.8 (HIGH). LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fi...
How severe is CVE-2026-69100?
CVE-2026-69100 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-69100?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.