Wxiaoqi · Spring-Cloud-Platform · CVE-2026-90594
**Name of the Vulnerable Software and Affected Versions**
wxiaoqi Spring-Cloud-Platform versions 3.0.1 through 3.1.0
**Description**
An issue in the Permission Service component allows for missing authorization. This occurs within the `PermissionService.checkUserPermission()` function located in the `/rpc/service/PermissionService.java` file, enabling remote exploitation.
**Recommendations**
As a temporary workaround, consider restricting the use of the `PermissionService.checkUserPermission()` function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.