zlt2000 microservices-platform 在 6.0.0 及之前版本中,存在一个授权缺失漏洞: 标志位默认值为 ,导致认证后的所有权限校验被禁用。因此,未分配任何角色的已认证用户能够通过绕过失效的授权机制,访问包括用户管理、角色分配以及 Elasticsearch 索引操作在内的管理类 API。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zlt2000 | microservices-platform | 0 ~ 6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92467 | 8.3 HIGH | microservices-platform through 6.0.0 Unverified Password Change via /users/password |
| CVE-2026-92469 | 8.1 HIGH | microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check |
| CVE-2026-92468 | 6.5 MEDIUM | microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center |
No comments yet