Description
GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

GoAdmin through 1.2.26 fails to properly anchor the logout pattern during permission checks, allowing an authenticated user to bypass authorization by appending a query string that includes the admin prefix followed by "/logout". When such a crafted request reaches an administrative endpoint, the system skips the intended permission check and grants access, enabling an attacker to read sensitive data or modify application state without proper authorization. The weakness is reflected in CWE‑863, which relates to missing authorization checks for a certain feature.

Affected Systems

The vulnerability affects the GoAdminGroup product GoAdmin, specifically all releases up to and including version 1.2.26. Users running any variant of this open‑source admin framework should verify whether they are running the affected version and plan an update if possible.

Risk and Exploitability

The CVSS score of 8.6 classifies this as high severity, but the EPSS score of less than 1% indicates a very low exploitation probability at present. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no publicly known exploits yet. The likely attack vector requires the attacker to be an authenticated user; once authenticated, they can manipulate the query string to reach privileged endpoints and perform unauthorized actions.

Generated by OpenCVE AI on September 17, 2026 at 23:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GoAdmin to version 1.2.27 or later, where the logout anchor check has been corrected so that query parameters cannot bypass permission checks.
  • If an immediate upgrade is not feasible, reconfigure the application or web server to strip or ignore query strings on logout and other admin routes, ensuring the URL path is the sole determinant of access control.
  • As a secondary measure, audit existing access control rules and implement logging that alerts on unexpected query string usage against administrative endpoints.
  • If possible, enforce least privilege for user accounts and perform regular reviews of granted permissions to limit the impact of any unauthorized access.

Generated by OpenCVE AI on September 17, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state.
Title GoAdmin through 1.2.26 Authorization Bypass via Query Parameter
First Time appeared Go-admin
Go-admin go-admin
Weaknesses CWE-863
CPEs cpe:2.3:a:go-admin:go-admin:*:*:*:*:*:*:*:*
Vendors & Products Go-admin
Go-admin go-admin
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Go-admin Go-admin
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:46:48.048Z

Reserved: 2026-09-16T19:40:20.184Z

Link: CVE-2026-92793

cve-icon Vulnrichment

Updated: 2026-09-17T13:46:42.363Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:28.923

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:15:16Z

Weaknesses