---
id: CVE-2026-90594
title: A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0
summary: >-
  A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0.
  This vulnerability affects the function PermissionService.checkUserPermission
  of the file /rpc/service/PermissionService.java of the component Permission
  Servic…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-862
  - CWE-863
vendor: wxiaoqi
product: Spring-Cloud-Platform
affected:
  - Spring-Cloud-Platform 3.0.1
  - Spring-Cloud-Platform 3.1.0
published: '2026-09-13'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:56:48.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90594'
references:
  - url: >-
      https://github.com/user-attachments/files/30627348/poc_vuln1_failopen_authz.zip
    label: cna@vuldb.com
  - url: 'https://github.com/wxiaoqi/Spring-Cloud-Platform/'
    label: cna@vuldb.com
  - url: 'https://github.com/wxiaoqi/Spring-Cloud-Platform/issues/64'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90594'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/913788'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403176'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403176/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T16:24:28.022518Z'
ingestedAt: '2026-09-14T15:23:07.468Z'
epss: 0.00366
epssPercentile: 0.27749
---

## Overview

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
