Junglewise Threat Intelligence

CVE-2026-90595: wxiaoqi Spring-Cloud-Platform auth bypass in OnlineController

CVE-2026-90595 · Severity: medium · CVSS 6.3 · Published 2026-09-13

Executive brief

wxiaoqi Spring-Cloud-Platform is an open-source microservices management platform built on Spring Cloud. A missing authorization flaw in the OnlineController.getOnlineInfo endpoint allows attackers to remotely access sensitive functionality without proper credentials, potentially exposing user session information and enabling unauthorized administrative operations.

Technical details

The vulnerability is a missing authorization (CWE-862) in the OnlineController.getOnlineInfo method located in aceModules/ace-admin/auth/controller/OnlineController.java. The endpoint fails to properly validate user permissions before returning online user session information, allowing any network-reachable attacker to call the function without authentication. The attack is remotely exploitable over the network with no special preconditions. An attacker can retrieve sensitive session data and potentially perform unauthorized actions. A proof-of-concept has been publicly released; the maintainers have not yet provided a patch despite early notification.

Affected products

  • wxiaoqi Spring-Cloud-Platform 1.0, 2.2, 3.0

Timeline

  • 2026-09-13: disclosed
  • other: Proof-of-concept released publicly

References

Related threats