Authorization Bypass in wxiaoqi Spring-Cloud-Platform Affects Permission Service
CVE-2026-90594
Key Information:
- Vendor
Wxiaoqi
- Status
- Vendor
- CVE Published:
- 13 September 2026
Badges
What is CVE-2026-90594?
A vulnerability exists in wxiaoqi's Spring-Cloud-Platform versions 3.0.1 and 3.1.0, specifically within the Permission Service's checkUserPermission function. This oversight allows remote attackers to manipulate the system, leading to unauthorized access. While the issue was reported to the project maintainers, no response has been documented, making this vulnerability particularly concerning as exploits are publicly accessible.
Affected Version(s)
Spring-Cloud-Platform 3.0.1
Spring-Cloud-Platform 3.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
