CVE Watchtower

← Back to CVE List

CVE-2026-90594NVD

Description

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity Level
MEDIUM (6.3)
Published Date
13/09/2026
Last Modified
14/09/2026
Exploitation Status
????
EPSS Score
0.21% (percentile 11.4%)

CVSS Base Metrics

CVSS v3 (3.1)
MEDIUM 6.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
CVSS v4 (4.0)
MEDIUM 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Weaknesses (CWE)

CWE-862 - Missing AuthorizationCWE-863 - Incorrect Authorization

Affected & Patched Versions

ProductAffected VersionsPatched Version
wxiaoqi Spring-Cloud-Platform3.0.1, 3.1.0N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.