Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated users without assigned roles can exploit this to create, edit, delete, publish and retract system-wide notices affecting arbitrary users and departments.
References
Configurations
No configuration.
History
16 Sep 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/stylefeng/Guns/issues/119 - |
16 Sep 2026, 17:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 17:18
Updated : 2026-09-16 18:17
NVD link : CVE-2026-92601
Mitre link : CVE-2026-92601
CVE.ORG link : CVE-2026-92601
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
