CVE-2026-94535: lamp-cloud through 5.10.0 Unauthorized Notification Deletion

Published Sep 21, 2026
·
Updated

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to permanently remove notifications belonging to other users without recipient validation.

Affected Software

1 affected component
lamp-cloud<=5.10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade lamp-cloud to a version that resolves this vulnerability.

    Fixed in 5.10.0
  2. Compensating control

    Restrict access to the DELETE /anyone/extendNotice/deleteMyNotice endpoint (and/or require proper authorization/recipient validation for notice IDs) so users cannot delete notifications belonging to other users.

Event History

Sep 21, 2026
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated user can exploit it. The attacker only needs a valid account and arbitrary notification IDs; no interaction from the notification recipient is required.

2

What is the impact of successful exploitation?

An attacker can permanently delete notifications belonging to other users. The reported impact is unauthorized modification and partial availability loss, with no stated confidentiality impact.

3

Which endpoint should defenders investigate?

Review DELETE requests to /anyone/extendNotice/deleteMyNotice, particularly requests where the authenticated caller is not the recipient or owner of the referenced notice ID. Check for unexpected notification deletions and mismatches between the requester and the deleted notification's recipient.

4

Are affected versions identified?

lamp-cloud through version 5.10.0 is reported as affected. The provided information does not identify a fixed version or a workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203