VulnSea

zlt2000 has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 8.2 (high).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.2
Publish → KEV
Last 90 days
4 prev 0

Products

  • microservices-platform 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

zlt2000 vulnerabilities

CVEs affecting zlt2000, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-92469High· 8.1PoC
6d ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifie…

Midnightzlt2000 · microservices-platformEPSS 0.50%via NVD
CVE-2026-92467High· 8.3PoC
6d ago

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. …

Midnightzlt2000 · microservices-platformEPSS 0.43%via NVD
CVE-2026-92468Medium· 6.5PoC
6d ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

Twilightzlt2000 · microservices-platformEPSS 0.37%via NVD
CVE-2026-92466High· 8.8PoC
6d ago

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated user…

Midnightzlt2000 · microservices-platformEPSS 0.85%via NVD
zlt2000 vulnerabilities (CVEs) · VulnSea