Description
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification. | |
| Title | microservices-platform through 6.0.0 Unverified Password Change via /users/password | |
| First Time appeared |
Zlt2000
Zlt2000 microservices-platform |
|
| Weaknesses | CWE-620 | |
| CPEs | cpe:2.3:a:zlt2000:microservices-platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zlt2000
Zlt2000 microservices-platform |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T13:16:43.820Z
Reserved: 2026-09-16T11:29:56.293Z
Link: CVE-2026-92467
No data.
Status : Deferred
Published: 2026-09-16T14:17:17.470
Modified: 2026-09-16T19:47:01.197
Link: CVE-2026-92467
No data.
OpenCVE Enrichment
Updated: 2026-09-17T05:00:13Z
Weaknesses
-
CWE-620
Unverified Password Change