Description
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including user management, role assignment, and Elasticsearch index operations by bypassing the disabled authorization enforcement.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 13:30:00 +0000
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T13:35:57.100Z
Reserved: 2026-09-16T11:29:51.513Z
Link: CVE-2026-92466
Updated: 2026-09-16T13:35:52.513Z
Status : Deferred
Published: 2026-09-16T14:17:17.313
Modified: 2026-09-16T19:47:01.197
Link: CVE-2026-92466
No data.
OpenCVE Enrichment
Updated: 2026-09-17T09:15:12Z
Weaknesses
-
CWE-862
Missing Authorization