Description
ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all recipients' read receipts without ownership validation.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass – Unauthorized Message Deletion
Action: Assess Impact
AI Analysis

Impact

The vulnerability is an authorization bypass in the user message deletion endpoint. The controller accepts a list of message identifiers without validating the requester's ownership of those messages, allowing any authenticated user to remove messages belonging to other users or announcements. This removal also deletes receipt records for all recipients, effectively erasing message history and potentially disrupting communications.

Affected Systems

ContiNew Admin version 4.1.0 is affected. Administrators and standard users alike can exploit the capability to delete messages they do not own, affecting the entire messaging subsystem within the application.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high risk, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The lack of a KEV listing also reduces the immediate prestige risk. However, the vulnerability requires only valid user credentials, making it relatively easy for attackers with legitimate accounts to carry out unauthorized deletions. The impact can include loss of critical information, disruption of user communication, and potential compliance violations.

Generated by OpenCVE AI on September 18, 2026 at 06:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Modify the delete endpoint to verify that the requesting user is the owner of each message or has administrator privileges before allowing deletion.
  • Refactor the access control layer so that only administrators or the message owner can perform delete operations, removing the global delete permission for all authenticated users.
  • Apply any vendor‑supplied patch or upgrade to a later release that resolves the ownership check flaw; if none is available, apply the above code changes as a custom fix.
  • Configure audit logging to capture message deletion attempts and regularly review logs for suspicious activity.

Generated by OpenCVE AI on September 18, 2026 at 06:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Continew admin
Vendors & Products Continew admin

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all recipients' read receipts without ownership validation.
Title ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageController
First Time appeared Continew
Continew continew Admin
Weaknesses CWE-639
CPEs cpe:2.3:a:continew:continew_admin:*:*:*:*:*:*:*:*
Vendors & Products Continew
Continew continew Admin
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Continew Admin Continew Admin
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:47.629Z

Reserved: 2026-09-16T13:48:49.970Z

Link: CVE-2026-92603

cve-icon Vulnrichment

Updated: 2026-09-18T18:08:13.387Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T17:18:20.733

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key