Description
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers can query arbitrary indices including sys_user to retrieve sensitive user records and password hashes without proper access controls.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure of Elasticsearch Indices
Action: Immediate Patch
AI Analysis

Impact

Authorized attackers can bypass authentication checks in the search-center service to read any Elasticsearch index by providing an index name in the POST /search/{indexName} request or the GET /agg/requestStat/{indexName}/{routing} URL. This allows the attacker to retrieve sensitive data, including user records and password hashes, from indices such as sys_user.

Affected Systems

The vulnerability affects the zlt2000 microservices-platform product, versions up to and including 6.0.0. No other versions were identified as vulnerable in the provided data.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity of data breach. The EPSS score of less than 1% suggests that exploitation is currently unlikely, yet the vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticated access to the microservices platform and can trigger the exploit by sending specific POST or GET requests to the search-center service. No additional system or network conditions are required, and the exploit path is fully documented in the references.

Generated by OpenCVE AI on September 18, 2026 at 05:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest microservices-platform release that resolves the search-center authorization bypass.
  • If a patch cannot be applied immediately, block or restrict network traffic to the /search and /agg endpoints to only trusted IP ranges or users.
  • Ensure only the minimum necessary privileges are granted to accounts that use the search-center service so they cannot read Elasticsearch indices.
  • Actively monitor logs for unauthorized access to Elasticsearch indices via the search-center endpoints.

Generated by OpenCVE AI on September 18, 2026 at 05:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers can query arbitrary indices including sys_user to retrieve sensitive user records and password hashes without proper access controls.
Title microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center
First Time appeared Zlt2000
Zlt2000 microservices-platform
Weaknesses CWE-639
CPEs cpe:2.3:a:zlt2000:microservices-platform:*:*:*:*:*:*:*:*
Vendors & Products Zlt2000
Zlt2000 microservices-platform
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Zlt2000 Microservices-platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:48:11.987Z

Reserved: 2026-09-16T11:30:01.283Z

Link: CVE-2026-92468

cve-icon Vulnrichment

Updated: 2026-09-18T17:48:05.691Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T14:17:17.620

Modified: 2026-09-18T18:18:11.933

Link: CVE-2026-92468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:00:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key