CVE-2026-90595 | wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0 OnlineController.java OnlineController.getOnlineInfo authorization (Issue 65)

SecurityVulns

A vulnerability was found in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0 and classified as critical. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization.

This vulnerability is identified as CVE-2026-90595. The attack can be executed remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More