Description
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and metadata by supplying their identifiers to the delete endpoint.
Published: 2026-09-16
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Deletion via Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the file-center module of the microservices-platform, specifically the DELETE /files/{id} endpoint. The endpoint performs no ownership validation, allowing an attacker who is authenticated to delete any file belonging to another user. This results in loss of data integrity and availability for affected files and associated metadata, with potential cascading effects on applications relying on those files.

Affected Systems

zlt2000 microservices-platform, versions up to and including 6.0.0, is affected by this authorization bypass. No further version information is provided by the CNA.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity, though the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at the present time. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires valid user credentials for the target system; attackers can enumerate file identifiers through GET /files and then issue DELETE requests with those identifiers to remove files of other users.

Generated by OpenCVE AI on September 18, 2026 at 05:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor-provided patch or upgrade to a version newer than 6.0.0.
  • If a patch is unavailable, reconfigure the DELETE /files/{id} endpoint to enforce ownership checks or restrict its use to administrative accounts only.
  • Restrict external access to the file‑center API or place it behind strict network segmentation to limit the exposure of the vulnerable endpoint.

Generated by OpenCVE AI on September 18, 2026 at 05:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and metadata by supplying their identifiers to the delete endpoint.
Title microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check
First Time appeared Zlt2000
Zlt2000 microservices-platform
Weaknesses CWE-639
CPEs cpe:2.3:a:zlt2000:microservices-platform:*:*:*:*:*:*:*:*
Vendors & Products Zlt2000
Zlt2000 microservices-platform
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Zlt2000 Microservices-platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T17:39:02.534Z

Reserved: 2026-09-16T11:30:06.209Z

Link: CVE-2026-92469

cve-icon Vulnrichment

Updated: 2026-09-16T17:38:57.066Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T14:17:17.767

Modified: 2026-09-24T20:48:01.433

Link: CVE-2026-92469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:00:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key