Missing Authorization in wxiaoqi Spring-Cloud-Platform Affects Remote Access
CVE-2026-90595
Key Information:
- Vendor
Wxiaoqi
- Status
- Vendor
- CVE Published:
- 13 September 2026
Badges
What is CVE-2026-90595?
A security flaw in wxiaoqi's Spring-Cloud-Platform affects the OnlineController.getOnlineInfo function, leading to missing authorization for remote requests. Attackers can exploit this flaw to gain unauthorized access to sensitive operations. Though the issue was reported early to the project maintainers, no public response has been noted. The vulnerability is critical for users of affected versions 1.0, 2.2, and 3.0, making it essential for administrators to take immediate action to secure their installations.
Affected Version(s)
Spring-Cloud-Platform 1.0
Spring-Cloud-Platform 2.2
Spring-Cloud-Platform 3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
