Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and metadata by supplying their identifiers to the delete endpoint. | |
| Title | microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check | |
| First Time appeared |
Zlt2000
Zlt2000 microservices-platform |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:zlt2000:microservices-platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zlt2000
Zlt2000 microservices-platform |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T17:39:02.534Z
Reserved: 2026-09-16T11:30:06.209Z
Link: CVE-2026-92469
Updated: 2026-09-16T17:38:57.066Z
Status : Received
Published: 2026-09-16T14:17:17.767
Modified: 2026-09-16T18:17:21.720
Link: CVE-2026-92469
No data.
OpenCVE Enrichment
No data.
