Vulnerability Description
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/LinYuanyi1/cve-request-poc/blob/master/microservice-platform/
- https://github.com/zlt2000/microservices-platform
- https://github.com/zlt2000/microservices-platform/blob/v6.0.0/zlt-business/user-
- https://github.com/zlt2000/microservices-platform/blob/v6.0.0/zlt-business/user-
- https://www.vulncheck.com/advisories/microservices-platform-through-6.0.0-unveri
FAQ
What is CVE-2026-92467?
CVE-2026-92467 is a vulnerability with a CVSS score of 8.3 (HIGH). zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by ...
How severe is CVE-2026-92467?
CVE-2026-92467 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-92467?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.