Description
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Password Credential Compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an authenticated user to change the password of any non-administrator account without providing the current password. By supplying an arbitrary user id in the request body, an attacker can overwrite another user’s credentials, effectively taking control of that account. This results in unauthorized access to the victim’s resources and potential escalation of privileges if the compromised account has elevated permissions.

Affected Systems

The affected product is the zlt2000 microservices‑platform released up to and including version 6.0.0. The flaw resides in the /users/password endpoint, specifically in the SysUserController and SysUserServiceImpl classes of the user‑center module. Only non‑administrator accounts are vulnerable, while administrator accounts appear to retain protection through separate workflow. No other versions are listed as affected.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, but the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a relatively low likelihood of exploitation in the wild at this time. The likely attack vector requires an attacker to be authenticated within the system; however, once authenticated, the attacker can supply any user id and new password, allowing rapid compromise of other accounts. No additional network or privilege escalation prerequisites are noted in the available information.

Generated by OpenCVE AI on September 18, 2026 at 05:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch that reinstates current password verification or upgrade to a version newer than 6.0.0 that removes the flaw.
  • If no patch is immediately available, configure the /users/password endpoint to enforce that the authenticated user’s id matches the target id or reject requests that modify other users’ credentials.
  • Monitor and audit password change logs for unexpected changes, and enable alerts for unauthorized password modifications to detect potential misuse early.

Generated by OpenCVE AI on September 18, 2026 at 05:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.
Title microservices-platform through 6.0.0 Unverified Password Change via /users/password
First Time appeared Zlt2000
Zlt2000 microservices-platform
Weaknesses CWE-620
CPEs cpe:2.3:a:zlt2000:microservices-platform:*:*:*:*:*:*:*:*
Vendors & Products Zlt2000
Zlt2000 microservices-platform
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Zlt2000 Microservices-platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T17:47:20.360Z

Reserved: 2026-09-16T11:29:56.293Z

Link: CVE-2026-92467

cve-icon Vulnrichment

Updated: 2026-09-21T17:47:13.048Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T14:17:17.470

Modified: 2026-09-21T18:17:15.050

Link: CVE-2026-92467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:00:04Z

Weaknesses
  • CWE-620

    Unverified Password Change