PT-2026-93732 · Git+1 · Microservices-Platform

·

CVE-2026-92466

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zlt2000 microservices-platform versions prior to 6.0.0
Description A missing authorization issue exists because the zlt.security.auth.urlPermission.enable flag defaults to false, which disables all permission checks following authentication. This allows authenticated users who have no assigned roles to bypass authorization enforcement and gain access to administrative APIs, including those used for user management, role assignment, and Elasticsearch index operations.
Recommendations Update zlt2000 microservices-platform to version 6.0.0 or later. Set the zlt.security.auth.urlPermission.enable flag to true to enable permission checks.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92466

Affected Products

Microservices-Platform