漏洞情报聚合

CVE-2026-75338 - disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center. - 漏洞详情

漏洞编号:CVE-2026-75338

风险等级:危急

漏洞来源:CVE

CVE 编号:CVE-2026-75338

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-284

发布/更新时间:2026-08-26 / 2026-08-27

漏洞描述

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center.

相关链接

相关漏洞

« 返回首页