← Back to search

CVE-2026-92466

8.8 HIGHpublic exploit available

Published 2026-09-16 · Updated 2026-09-16

AI risk analysis

Summary
The flaw allows authenticated users without roles to access administrative APIs, leading to unauthorized access and potential data manipulation.
Exploitability
Exploitation is relatively easy given that the vulnerability is enabled by default and no roles are required for access.
Blast radius
If exploited, this could result in unauthorized changes to user management, role assignments, and Elasticsearch configurations, leading to significant data and operational risks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to zlt2000 microservices-platform 6.1.0 or later.
auth-bypassapiadminmicroservices

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including user management, role assignment, and Elasticsearch index operations by bypassing the disabled authorization enforcement.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-862

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.