Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification. | |
| Title | microservices-platform through 6.0.0 Unverified Password Change via /users/password | |
| First Time appeared |
Zlt2000
Zlt2000 microservices-platform |
|
| Weaknesses | CWE-620 | |
| CPEs | cpe:2.3:a:zlt2000:microservices-platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zlt2000
Zlt2000 microservices-platform |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T13:16:43.820Z
Reserved: 2026-09-16T11:29:56.293Z
Link: CVE-2026-92467
No data.
Status : Received
Published: 2026-09-16T14:17:17.470
Modified: 2026-09-16T14:17:17.470
Link: CVE-2026-92467
No data.
OpenCVE Enrichment
No data.