bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the synccount endpoint to trigger expensive full-table user recounts and cache invalidations, causing denial of service through repeated concurrent database operations.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the synccount endpoint to trigger expensive full-table user recounts and cache invalidations, causing denial of service through repeated concurrent database operations. | |
| Title | bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount | |
| First Time appeared |
Bbs-go Project
Bbs-go Project bbs-go |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:bbs-go_project:bbs-go:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bbs-go Project
Bbs-go Project bbs-go |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T14:48:56.405Z
Reserved: 2026-09-30T14:28:17.453Z
Link: CVE-2026-103396
No data.
Status : Received
Published: 2026-09-30T15:22:28.093
Modified: 2026-09-30T15:22:28.093
Link: CVE-2026-103396
No data.
OpenCVE Enrichment
No data.
Weaknesses