zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including user management, role assignment, and Elasticsearch index operations by bypassing the disabled authorization enforcement.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 13:30:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T13:35:57.100Z
Reserved: 2026-09-16T11:29:51.513Z
Link: CVE-2026-92466
Updated: 2026-09-16T13:35:52.513Z
Status : Deferred
Published: 2026-09-16T14:17:17.313
Modified: 2026-09-16T19:47:01.197
Link: CVE-2026-92466
No data.
OpenCVE Enrichment
No data.
Weaknesses