Description
A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to online session info
Action: Restrict Access
AI Analysis

Impact

The vulnerability is an authorization bypass in OnlineController.getOnlineInfo of wxiaoqi Spring-Cloud-Platform. It allows remote actors to obtain user session or online information without proper authentication or authorization. This missing authorization weakness (CWE-862) and authorization bypass weakness (CWE-863) can expose potentially sensitive user data. Affected products include wxiaoqi Spring-Cloud-Platform releases 1.0, 2.2, and 3.0, where the vulnerable logic resides in aceModules/ace-admin/auth/controller/OnlineController.java. No patch has been released by the vendor, who has yet to respond to reported issues. The risk is moderate, with a CVSS score of 5.3 and an EPSS score of < 1%. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it remotely by sending a crafted request to the /online-info endpoint; a public proof‑of‑concept demonstrates this capability without requiring special credentials.

Affected Systems

Affected products are wxiaoqi Spring-Cloud-Platform releases 1.0, 2.2, and 3.0, which include the insecure OnlineController method in the aceModules/ace-admin/auth/controller package. Any deployment of these specific releases is vulnerable. There are no additional sub‑versions or hotfixes mentioned, and the project has not yet released a fix.

Risk and Exploitability

The vulnerability is moderately risky. With no EPSS score disclosed beyond the notation of < 1% and its absence from the CISA KEV catalog, the public exploit release indicates that attacker tools are available, but widespread targeting seems limited. An attacker can perform the exploit remotely by crafting a request to the vulnerable endpoint, and the GitHub proof‑of‑concept shows that no special environment is required. Administrators should treat this as a moderate threat that could let attackers gather additional user session information.

Generated by OpenCVE AI on September 15, 2026 at 16:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any official patch or code fix released by wxiaoqi as soon as it becomes available.
  • Block or restrict external traffic to the /online-info endpoint at the perimeter firewall or API gateway, allowing only trusted hosts or IP ranges to access it.
  • Ensure that the OnlineController.getOnlineInfo method enforces role‑based or permission checks before returning data, so that only users with appropriate privileges can invoke it.
  • Monitor application logs for repeated or suspicious requests to the online-info endpoint and investigate any unauthorized access attempts.

Generated by OpenCVE AI on September 15, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title wxiaoqi Spring-Cloud-Platform OnlineController.java OnlineController.getOnlineInfo authorization
First Time appeared Wxiaoqi
Wxiaoqi spring-cloud-platform
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:wxiaoqi:spring-cloud-platform:*:*:*:*:*:*:*:*
Vendors & Products Wxiaoqi
Wxiaoqi spring-cloud-platform
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wxiaoqi Spring-cloud-platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:59:05.177Z

Reserved: 2026-09-12T18:26:43.751Z

Link: CVE-2026-90595

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:24.466Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T21:17:03.173

Modified: 2026-09-15T14:17:20.673

Link: CVE-2026-90595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses