zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers can query arbitrary indices including sys_user to retrieve sensitive user records and password hashes without proper access controls.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers can query arbitrary indices including sys_user to retrieve sensitive user records and password hashes without proper access controls. | |
| Title | microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center | |
| First Time appeared |
Zlt2000
Zlt2000 microservices-platform |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:zlt2000:microservices-platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zlt2000
Zlt2000 microservices-platform |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T13:16:44.539Z
Reserved: 2026-09-16T11:30:01.283Z
Link: CVE-2026-92468
No data.
Status : Deferred
Published: 2026-09-16T14:17:17.620
Modified: 2026-09-16T19:47:01.197
Link: CVE-2026-92468
No data.
OpenCVE Enrichment
No data.
Weaknesses