CVE-2026-69100: LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LAMP 5.6.2 GlueFactoryto a version that resolves this vulnerability.Fixed in 5.6.2Patch 84b0c27
Event History
Frequently Asked Questions
What is the severity of CVE-2026-69100?
The severity of CVE-2026-69100 is high with a score of 8.8.
How do I fix CVE-2026-69100?
To fix CVE-2026-69100, you should upgrade to LAMP Rapid Development Platform version 5.6.3 or later, which contains the fix.
What type of vulnerability is CVE-2026-69100?
CVE-2026-69100 is a remote code execution vulnerability caused by unsandboxed Groovy scripts being executed.
What impact does CVE-2026-69100 have on my system?
CVE-2026-69100 can allow attackers to execute arbitrary code on your system, potentially leading to complete system compromise.
Which versions of LAMP are affected by CVE-2026-69100?
CVE-2026-69100 affects LAMP Rapid Development Platform versions up to and including 5.6.2.