High severity8.1NVD Advisory· Published Sep 16, 2026
CVE-2026-92793
CVE-2026-92793
Description
GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=1.2.26
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.