CVE-2026-90594 | wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0 Permission Service PermissionService.java PermissionService.checkUserPermission authorization (Issue 64)
A vulnerability has been found in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0 and classified as critical. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2026-90594. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More