MEDIUM
CVE-2026-90594
CVSS
6.3
Description
A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Weakness (CWE)
CWE-862
Missing Authorization
CWE-863
Incorrect Authorization
EPSS Score
0.21%
Probability of exploitation in next 30 days
11.5th percentile
References
https://github.com/user-attachments/files/30627348/poc_vuln1_failopen_authz.zip
https://github.com/wxiaoqi/Spring-Cloud-Platform/
https://github.com/wxiaoqi/Spring-Cloud-Platform/issues/64
https://vuldb.com/cve/CVE-2026-90594
https://vuldb.com/submit/913788
https://vuldb.com/vuln/403176
https://vuldb.com/vuln/403176/cti
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.