HIGH 7.1 NVD
CVE-2026-92468
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers can query arbitrary indices including sys_user to retrieve sensitive user records and password hashes without proper access controls.
References
- https://github.com/LinYuanyi1/cve-request-poc/blob/master/microservice-platform/C22_reques
- https://github.com/LinYuanyi1/cve-request-poc/blob/master/microservice-platform/C24_search
- https://github.com/zlt2000/microservices-platform
- https://github.com/zlt2000/microservices-platform/blob/v6.0.0/zlt-business/search-center/s
- https://github.com/zlt2000/microservices-platform/blob/v6.0.0/zlt-business/search-center/s
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14391 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.