PatchSiren

zlt2000 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH zlt2000 CVE published 2026-09-16

CVE-2026-92468

The CVE-2026-92468 vulnerability in the zlt2000 microservices-platform allows authenticated attackers to read any Elasticsearch index, potentially exposing sensitive user records and password hashes. This issue arises from an authorization bypass in the search-center service, enabling attackers to query arbitrary indices, including sys_user, without proper access controls.