zlt2000 微服务平台在 6.0.0 及更早版本中,search-center 服务存在授权绕过漏洞。经过身份验证的攻击者可以通过在 POST /search/{indexName} 和 GET /agg/requestStat/{indexName}/{routing} 接口的路径变量中指定索引名称,读取任意 Elasticsearch 索引。由于缺乏适当的访问控制,攻击者可以查询包括 sys_user 在内的任意索引,从而获取敏感的用户记录和密码哈希值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zlt2000 | microservices-platform | 0 ~ 6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92466 | 8.8 HIGH | microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Che |
| CVE-2026-92467 | 8.3 HIGH | microservices-platform through 6.0.0 Unverified Password Change via /users/password |
| CVE-2026-92469 | 8.1 HIGH | microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check |
No comments yet