Description
A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Missing Authorization leading to privilege escalation
Action: Assess Impact
AI Analysis

Impact

The vulnerability is located in the PermissionService.checkUserPermission method of wxiaoqi Spring-Cloud-Platform. An attacker can manipulate the RPC request to bypass authorization logic, which is an Authorization Bypass (CWE‑862) and a Permission Check Failure (CWE‑863). The result is that remote users may access protected resources or functionalities that they should not be allowed to use. Public exploits are available, meaning the attack is feasible in real‑world scenarios.

Affected Systems

Affected systems include wxiaoqi's Spring‑Cloud‑Platform version 3.0.1 and 3.1.0. The flaw exists in the Permission Service component, specifically the PermissionService.java file. No other versions have been identified; the vulnerability is not listed in the CISA KEV catalog. If your deployment uses either of these releases, it is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is below 1%, which suggests the current likelihood of exploitation is very low, but it is not unavailable. The vulnerability is not yet listed in the KEV catalog, indicating it may not have widespread exploitation, yet publicly available proofs of concept exist. The most likely attack vector is remote exploitation via the exposed RPC PermissionService endpoint, where an attacker can send crafted requests to trigger the missing authorization check.

Generated by OpenCVE AI on September 15, 2026 at 16:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑released patch or upgrade to a non‑affected release of Spring‑Cloud‑Platform when it becomes available.
  • Configure the PermissionService RPC endpoint to allow only authenticated users with the correct roles, thereby reducing the attack surface.
  • Add supplementary application‑level authorization logic for resources that rely on PermissionService.checkUserPermission to compensate for the missing check.
  • Enable monitoring of RPC calls for anomalous permission checks and configure alerts for any unauthorized activity.

Generated by OpenCVE AI on September 15, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Title wxiaoqi Spring-Cloud-Platform Permission Service PermissionService.java PermissionService.checkUserPermission authorization
First Time appeared Wxiaoqi
Wxiaoqi spring-cloud-platform
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:wxiaoqi:spring-cloud-platform:*:*:*:*:*:*:*:*
Vendors & Products Wxiaoqi
Wxiaoqi spring-cloud-platform
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wxiaoqi Spring-cloud-platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T16:24:40.937Z

Reserved: 2026-09-12T18:26:39.486Z

Link: CVE-2026-90594

cve-icon Vulnrichment

Updated: 2026-09-14T16:24:37.147Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T21:17:02.980

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses