VulnSea

microservices-platform vulnerabilities

CVEs whose affected-version data names the microservices-platform package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-92469High· 8.1PoC
6d ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifie…

Midnightzlt2000 · microservices-platformEPSS 0.50%via NVD
CVE-2026-92467High· 8.3PoC
6d ago

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. …

Midnightzlt2000 · microservices-platformEPSS 0.43%via NVD
CVE-2026-92468Medium· 6.5PoC
6d ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

Twilightzlt2000 · microservices-platformEPSS 0.37%via NVD
CVE-2026-92466High· 8.8PoC
6d ago

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated user…

Midnightzlt2000 · microservices-platformEPSS 0.85%via NVD
microservices-platform vulnerabilities (CVEs) · VulnSea