Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the synccount endpoint to trigger expensive full-table user recounts and cache invalidations, causing denial of service through repeated concurrent database operations. | |
| Title | bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount | |
| First Time appeared |
Bbs-go Project
Bbs-go Project bbs-go |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:bbs-go_project:bbs-go:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bbs-go Project
Bbs-go Project bbs-go |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T14:48:56.405Z
Reserved: 2026-09-30T14:28:17.453Z
Link: CVE-2026-103396
No data.
Status : Received
Published: 2026-09-30T15:22:28.093
Modified: 2026-09-30T15:22:28.093
Link: CVE-2026-103396
No data.
OpenCVE Enrichment
No data.