CVE-2026-86118

gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 10:16

Updated : 2026-09-16 13:42


NVD link : CVE-2026-86118

Mitre link : CVE-2026-86118

CVE.ORG link : CVE-2026-86118


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization