<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:zlt2000:microservices-Platform:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3azlt2000microservices-platform/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 15:50:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3azlt2000microservices-platform/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in zlt2000 microservices-platform</title><link>https://feed.craftedsignal.io/briefs/2026-09-zlt2000-auth-bypass/</link><pubDate>Wed, 16 Sep 2026 15:50:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-zlt2000-auth-bypass/</guid><description>A default configuration vulnerability in zlt2000 microservices-platform through 6.0.0 disables URL permission checks, allowing authenticated users to perform unauthorized administrative actions.</description><content:encoded><![CDATA[<p>The zlt2000 microservices-platform, version 6.0.0 and earlier, contains a critical security configuration vulnerability (CVE-2026-92466). The platform defaults the 'zlt.security.auth.urlPermission.enable' configuration flag to 'false'. When this flag is disabled, the platform fails to enforce URL-level permission checks for authenticated sessions. This flaw essentially renders the role-based access control (RBAC) mechanism ineffective, allowing any successfully authenticated user - regardless of their assigned roles or privileges - to interact with sensitive administrative endpoints. This exposure permits unauthorized users to perform administrative tasks, including managing user accounts, modifying role assignments, and interacting directly with Elasticsearch index operations, posing a significant risk of privilege escalation and unauthorized data manipulation within the microservices environment.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for complete unauthorized administrative access to the platform's backend services. An attacker who gains low-privileged credentials can escalate privileges to perform administrative actions, potentially leading to full system compromise, exfiltration of data via Elasticsearch index access, and the modification of user accounts to maintain persistent, high-privileged access.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and IT teams:</p>
<ul>
<li>Apply the configuration update by setting 'zlt.security.auth.urlPermission.enable' to 'true' in the platform's configuration file immediately.</li>
<li>Audit administrative audit logs to identify any unexpected access to sensitive API endpoints such as '/api/user/manage' or Elasticsearch management interfaces initiated by low-privileged user accounts.</li>
<li>Review all user accounts and role assignments for unauthorized modifications performed during the period the platform was running with the default configuration.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>privilege-escalation</category><category>web-application</category></item></channel></rss>