disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 23:17
Updated : 2026-09-09 16:04
NVD link : CVE-2026-75338
Mitre link : CVE-2026-75338
CVE.ORG link : CVE-2026-75338
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
