8.8
CVE-2026-92466
- EPSS 0.85%
- Veröffentlicht 16.09.2026 13:16:43
- Zuletzt bearbeitet 16.09.2026 19:47:01
- Erkennungen
microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Checking
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including user management, role assignment, and Elasticsearch index operations by bypassing the disabled authorization enforcement.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerzlt2000
≫
Produkt
microservices-platform
Default Statusunaffected
Version <=
6.0.0
Version
0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.85% | 0.565 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/zlt2000/microservices-platform/blob/v6.0.0/zlt-commons/zlt-auth-client-spring-boot-starter/src/main/java/com/central/oauth2/common/service/impl/DefaultPermissionServiceImpl.java#L59
https://github.com/zlt2000/microservices-platform/blob/v6.0.0/zlt-commons/zlt-auth-client-spring-boot-starter/src/main/java/com/central/oauth2/common/properties/UrlPermissionProperties.java#L25
https://github.com/zlt2000/microservices-platform/blob/v6.0.0/zlt-gateway/sc-gateway/src/main/resources/application.yml#L122
https://github.com/LinYuanyi1/cve-request-poc/blob/master/microservice-platform/C06_set_role_to_user.py
https://github.com/LinYuanyi1/cve-request-poc/blob/master/microservice-platform/C11_list_all_users.py
https://github.com/LinYuanyi1/cve-request-poc/blob/master/microservice-platform/C10_reset_password_by_id.py
https://github.com/LinYuanyi1/cve-request-poc/blob/master/microservice-platform/C04_save_or_update_user.py
https://github.com/LinYuanyi1/cve-request-poc/blob/master/microservice-platform/C21_delete_es_index.py
https://github.com/zlt2000/microservices-platform
https://www.vulncheck.com/advisories/microservices-platform-through-6.0.0-missing-authorization-via-disabled-url-permission-checking