CVE-2026-92601

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated users without assigned roles can exploit this to create, edit, delete, publish and retract system-wide notices affecting arbitrary users and departments.
Configurations

No configuration.

History

16 Sep 2026, 18:17

Type Values Removed Values Added
References () https://github.com/stylefeng/Guns/issues/119 - () https://github.com/stylefeng/Guns/issues/119 -

16 Sep 2026, 17:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 17:18

Updated : 2026-09-16 18:17


NVD link : CVE-2026-92601

Mitre link : CVE-2026-92601

CVE.ORG link : CVE-2026-92601


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization