Impact
GoAdmin through 1.2.26 fails to properly anchor the logout pattern during permission checks, allowing an authenticated user to bypass authorization by appending a query string that includes the admin prefix followed by "/logout". When such a crafted request reaches an administrative endpoint, the system skips the intended permission check and grants access, enabling an attacker to read sensitive data or modify application state without proper authorization. The weakness is reflected in CWE‑863, which relates to missing authorization checks for a certain feature.
Affected Systems
The vulnerability affects the GoAdminGroup product GoAdmin, specifically all releases up to and including version 1.2.26. Users running any variant of this open‑source admin framework should verify whether they are running the affected version and plan an update if possible.
Risk and Exploitability
The CVSS score of 8.6 classifies this as high severity, but the EPSS score of less than 1% indicates a very low exploitation probability at present. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no publicly known exploits yet. The likely attack vector requires the attacker to be an authenticated user; once authenticated, they can manipulate the query string to reach privileged endpoints and perform unauthorized actions.
OpenCVE Enrichment