CVE-2026-92466 PUBLISHED

microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Checking

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including user management, role assignment, and Elasticsearch index operations by bypassing the disabled authorization enforcement.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor zlt2000
Product microservices-platform
Versions Default: unaffected
  • affected from 0 to 6.0.0 (incl.)

Credits

  • Mingsheng Lin finder

References

Problem Types

  • Missing Authorization CWE