Beveiligingsadvies

CVE-2026-92469

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-16 13:16:45
Laatst bijgewerkt 2026-09-16 17:39:02
Toegewezen door VulnCheck
CVSS-score 8.1
Status PUBLISHED

Beschrijving

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and metadata by supplying their identifiers to the delete endpoint.