Authorization Bypass in zlt2000 Microservices Platform File Center Module
CVE-2026-92469
Key Information:
- Vendor
Zlt2000
- Status
- Vendor
- CVE Published:
- 16 September 2026
Badges
What is CVE-2026-92469?
The zlt2000 microservices-platform's file-center module up to version 6.0.0 contains a significant vulnerability that allows authenticated users to delete files belonging to other users. The DELETE /files/{id} endpoint lacks proper ownership verification, enabling attackers to exploit this oversight. By enumerating file identifiers via the GET /files endpoint, they can issue delete requests for any user's files and associated metadata. This defect poses a serious risk to user data integrity and confidentiality.
Affected Version(s)
microservices-platform 0 <= 6.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
