MEDIUM
CVE-2026-90595
CVSS
6.3
Description
A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Weakness (CWE)
CWE-862
Missing Authorization
CWE-863
Incorrect Authorization
EPSS Score
0.21%
Probability of exploitation in next 30 days
11.5th percentile
References
https://github.com/user-attachments/files/30627379/poc_vuln2_session_exposure.zip
https://github.com/wxiaoqi/Spring-Cloud-Platform/
https://github.com/wxiaoqi/Spring-Cloud-Platform/issues/65
https://vuldb.com/cve/CVE-2026-90595
https://vuldb.com/submit/913789
https://vuldb.com/vuln/403177
https://vuldb.com/vuln/403177/cti
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.