{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/zlt2000/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zlt2000:microservices-platform:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92466"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["microservices-platform (\u003c= 6.0.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","web-application"],"_cs_type":"advisory","_cs_vendors":["zlt2000"],"content_html":"\u003cp\u003eThe zlt2000 microservices-platform, version 6.0.0 and earlier, contains a critical security configuration vulnerability (CVE-2026-92466). The platform defaults the 'zlt.security.auth.urlPermission.enable' configuration flag to 'false'. When this flag is disabled, the platform fails to enforce URL-level permission checks for authenticated sessions. This flaw essentially renders the role-based access control (RBAC) mechanism ineffective, allowing any successfully authenticated user - regardless of their assigned roles or privileges - to interact with sensitive administrative endpoints. This exposure permits unauthorized users to perform administrative tasks, including managing user accounts, modifying role assignments, and interacting directly with Elasticsearch index operations, posing a significant risk of privilege escalation and unauthorized data manipulation within the microservices environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for complete unauthorized administrative access to the platform's backend services. An attacker who gains low-privileged credentials can escalate privileges to perform administrative actions, potentially leading to full system compromise, exfiltration of data via Elasticsearch index access, and the modification of user accounts to maintain persistent, high-privileged access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eApply the configuration update by setting 'zlt.security.auth.urlPermission.enable' to 'true' in the platform's configuration file immediately.\u003c/li\u003e\n\u003cli\u003eAudit administrative audit logs to identify any unexpected access to sensitive API endpoints such as '/api/user/manage' or Elasticsearch management interfaces initiated by low-privileged user accounts.\u003c/li\u003e\n\u003cli\u003eReview all user accounts and role assignments for unauthorized modifications performed during the period the platform was running with the default configuration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T15:50:43Z","date_published":"2026-09-16T15:50:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zlt2000-auth-bypass/","summary":"A default configuration vulnerability in zlt2000 microservices-platform through 6.0.0 disables URL permission checks, allowing authenticated users to perform unauthorized administrative actions.","title":"Authorization Bypass in zlt2000 microservices-platform","url":"https://feed.craftedsignal.io/briefs/2026-09-zlt2000-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Zlt2000","version":"https://jsonfeed.org/version/1.1"}