HIGH 8.7 NVD
CVE-2026-92467
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.
References
- https://github.com/LinYuanyi1/cve-request-poc/blob/master/microservice-platform/C09_reset_
- https://github.com/zlt2000/microservices-platform
- https://github.com/zlt2000/microservices-platform/blob/v6.0.0/zlt-business/user-center/src
- https://github.com/zlt2000/microservices-platform/blob/v6.0.0/zlt-business/user-center/src
- https://www.vulncheck.com/advisories/microservices-platform-through-6.0.0-unverified-passw
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14391 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.