GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state. | |
| Title | GoAdmin through 1.2.26 Authorization Bypass via Query Parameter | |
| First Time appeared |
Go-admin
Go-admin go-admin |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:go-admin:go-admin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Go-admin
Go-admin go-admin |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:48.293Z
Reserved: 2026-09-16T19:40:20.184Z
Link: CVE-2026-92793
No data.
Status : Received
Published: 2026-09-16T21:17:28.923
Modified: 2026-09-16T21:17:28.923
Link: CVE-2026-92793
No data.
OpenCVE Enrichment
No data.
Weaknesses