HIGH
zlt2000
CVE published 2026-09-16
CVE-2026-92468
The CVE-2026-92468 vulnerability in the zlt2000 microservices-platform allows authenticated attackers to read any Elasticsearch index, potentially exposing sensitive user records and password hashes. This issue arises from an authorization bypass in the search-center service, enabling attackers to query arbitrary indices, including sys_user, without proper access controls.