zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and metadata by supplying their identifiers to the delete endpoint.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and metadata by supplying their identifiers to the delete endpoint. | |
| Title | microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check | |
| First Time appeared |
Zlt2000
Zlt2000 microservices-platform |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:zlt2000:microservices-platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zlt2000
Zlt2000 microservices-platform |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T13:16:45.272Z
Reserved: 2026-09-16T11:30:06.209Z
Link: CVE-2026-92469
No data.
Status : Received
Published: 2026-09-16T14:17:17.767
Modified: 2026-09-16T14:17:17.767
Link: CVE-2026-92469
No data.
OpenCVE Enrichment
No data.
Weaknesses