PT-2026-93732 · Git+1 · Microservices-Platform
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
zlt2000 microservices-platform versions prior to 6.0.0
Description
A missing authorization issue exists because the
zlt.security.auth.urlPermission.enable flag defaults to false, which disables all permission checks following authentication. This allows authenticated users who have no assigned roles to bypass authorization enforcement and gain access to administrative APIs, including those used for user management, role assignment, and Elasticsearch index operations.Recommendations
Update zlt2000 microservices-platform to version 6.0.0 or later.
Set the
zlt.security.auth.urlPermission.enable flag to true to enable permission checks.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microservices-Platform