gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 10:16
Updated : 2026-09-16 13:42
NVD link : CVE-2026-86118
Mitre link : CVE-2026-86118
CVE.ORG link : CVE-2026-86118
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
