Junglewise Threat Intelligence

CVE-2026-90594: wxiaoqi Spring-Cloud-Platform authorization bypass in Permission Service

CVE-2026-90594 · Severity: medium · CVSS 6.3 · Published 2026-09-13

Executive brief

Spring-Cloud-Platform is a microservices management platform that provides role-based access control (RBAC) for enterprise applications. A vulnerability in the permission checking logic allows remote attackers to bypass authorization controls and access functionality they should not be permitted to use, potentially leading to unauthorized data access or administrative actions.

Technical details

A missing authorization vulnerability exists in the PermissionService.checkUserPermission function within the Permission Service component. The flaw allows remote attackers to bypass permission checks without authentication, enabling unauthorized access to protected operations. The vulnerable code is located in /rpc/service/PermissionService.java. Exploitation is possible over the network and does not require prior authentication. A public proof-of-concept exploit is available, indicating active awareness in the security community. The project maintainer has been notified but has not yet released a patch.

Affected products

  • wxiaoqi Spring-Cloud-Platform 3.0.1, 3.1.0

Timeline

  • 2026-09-13: disclosed

References

Related threats