


Perceptive Security
SOC/SIEM Consultancy

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed …
Published:
4 augustus 2026 om 00:00:00
Alert date:
4 augustus 2026 om 19:02:19
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities
LAMP Rapid Development Platform versions through 5.6.2 contain a critical remote code execution vulnerability in the GlueFactory component. The flaw allows execution of unsandboxed Groovy scripts sourced from database template fields without any compilation restrictions or whitelisting controls. Attackers who can write to or influence the script field via message template endpoints can execute arbitrary Groovy code and OS commands on the backend server. The vulnerability was fixed in commit 84b0c27d3693e468c2c690d9fbc8ea9c22cd34e3. The issue is tracked as CVE-2026-69100 and has been reported via GitHub issues and documented by VulnCheck. Organizations using LAMP Rapid Development Platform should update immediately to a patched version to mitigate risk of full server compromise.
Technical details
Mitigation steps:
Affected products:
LAMP Rapid Development Platform
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69100
https://github.com/dromara/lamp-cloud/commit/84b0c27d3693e468c2c690d9fbc8ea9c22cd34e3
https://github.com/dromara/lamp-cloud/issues/408
https://www.vulncheck.com/advisories/lamp-gluefactory-unsandboxed-groovy-script-remote-code-execution
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
