CVE-2026-92469
- EPSS 0.5%
- Veröffentlicht 16.09.2026 13:16:45
- Zuletzt bearbeitet 24.09.2026 20:48:01
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /f...
CVE-2026-92468
- EPSS 0.37%
- Veröffentlicht 16.09.2026 13:16:44
- Zuletzt bearbeitet 18.09.2026 18:18:11
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and ...
CVE-2026-92466
- EPSS 0.85%
- Veröffentlicht 16.09.2026 13:16:43
- Zuletzt bearbeitet 16.09.2026 19:47:01
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no rol...
CVE-2026-92467
- EPSS 0.43%
- Veröffentlicht 16.09.2026 13:16:43
- Zuletzt bearbeitet 21.09.2026 18:17:15
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can...
CVE-2025-8841
- EPSS 0.3%
- Veröffentlicht 11.08.2025 10:15:33
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation l...