CVE-2026-92467

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.
Configurations

No configuration.

History

16 Sep 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 14:17

Updated : 2026-09-16 14:17


NVD link : CVE-2026-92467

Mitre link : CVE-2026-92467

CVE.ORG link : CVE-2026-92467


JSON object : View

Products Affected

No product.

CWE
CWE-620

Unverified Password Change