zlt2000 microservices-platform 版本(6.0.0 及之前)在 端点中存在一个未经验证的密码修改漏洞。该漏洞允许已认证的用户通过省略当前密码校验,从而能够修改任意账户的密码。 具体而言,攻击者可以在请求体中指定任意的用户 ID 并传入一个新密码,即可在不进行身份验证的情况下,覆盖任意非管理员账户的登录凭证(即“忘记密码”逻辑中未校验旧密码,且未严格限制操作者权限)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zlt2000 | microservices-platform | 0 ~ 6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92466 | 8.8 HIGH | microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Che |
| CVE-2026-92469 | 8.1 HIGH | microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check |
| CVE-2026-92468 | 6.5 MEDIUM | microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center |
No comments yet