{"id":"CVE-2026-16217","summary":"guohongze adminset Delivery Deployment Endpoint deli.py authorization","details":"A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the argument project_id leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.","modified":"2026-07-21T03:42:10.176653422Z","published":"2026-07-19T05:30:10.201Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-285","CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16217.json","unresolved_ranges":[{"extracted_events":[{"introduced":"0.8"},{"last_affected":"0.8"},{"introduced":"0.9"},{"last_affected":"0.9"},{"introduced":"0.10"},{"last_affected":"0.10"},{"introduced":"0.13"},{"last_affected":"0.13"},{"introduced":"0.14"},{"last_affected":"0.14"},{"introduced":"0.15"},{"last_affected":"0.15"},{"introduced":"0.16"},{"last_affected":"0.16"},{"introduced":"0.17"},{"last_affected":"0.17"},{"introduced":"0.18"},{"last_affected":"0.18"},{"introduced":"0.19"},{"last_affected":"0.19"},{"introduced":"0.28"},{"last_affected":"0.28"},{"introduced":"0.29"},{"last_affected":"0.29"},{"introduced":"0.36"},{"last_affected":"0.36"},{"introduced":"0.42"},{"last_affected":"0.42"},{"introduced":"0.43"},{"last_affected":"0.43"},{"introduced":"0.44"},{"last_affected":"0.44"},{"introduced":"0.45"},{"last_affected":"0.45"},{"introduced":"0.46"},{"last_affected":"0.46"},{"introduced":"0.47"},{"last_affected":"0.47"},{"introduced":"0.48"},{"last_affected":"0.48"},{"introduced":"0.49"},{"last_affected":"0.49"},{"introduced":"0.52"},{"last_affected":"0.52"},{"introduced":"0.57"},{"last_affected":"0.57"},{"introduced":"0.58"},{"last_affected":"0.58"},{"introduced":"0.59"},{"last_affected":"0.59"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/guohongze/adminset/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16217.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16217"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-16217"},{"type":"ADVISORY","url":"https://vuldb.com/submit/857950"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/380040"},{"type":"REPORT","url":"https://github.com/guohongze/adminset/issues/161"},{"type":"REPORT","url":"https://vuldb.com/vuln/380040/cti"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/guohongze/adminset","events":[{"introduced":"d1b6c5907b91d3cd062a1b239703188c7a920ff2"},{"last_affected":"6b291538e61c8a11c282815a26d6a1a4d691f6cf"}],"database_specific":{"extracted_events":[{"introduced":"0.1"},{"last_affected":"0.1"},{"introduced":"0.2"},{"last_affected":"0.2"},{"introduced":"0.3"},{"last_affected":"0.3"},{"introduced":"0.4"},{"last_affected":"0.4"},{"introduced":"0.5"},{"last_affected":"0.5"},{"introduced":"0.6"},{"last_affected":"0.6"},{"introduced":"0.7"},{"last_affected":"0.7"},{"introduced":"0.11"},{"last_affected":"0.11"},{"introduced":"0.12"},{"last_affected":"0.12"},{"introduced":"0.20"},{"last_affected":"0.20"},{"introduced":"0.21"},{"last_affected":"0.21"},{"introduced":"0.22"},{"last_affected":"0.22"},{"introduced":"0.23"},{"last_affected":"0.23"},{"introduced":"0.24"},{"last_affected":"0.24"},{"introduced":"0.25"},{"last_affected":"0.25"},{"introduced":"0.26"},{"last_affected":"0.26"},{"introduced":"0.27"},{"last_affected":"0.27"},{"introduced":"0.30"},{"last_affected":"0.30"},{"introduced":"0.31"},{"last_affected":"0.31"},{"introduced":"0.32"},{"last_affected":"0.32"},{"introduced":"0.33"},{"last_affected":"0.33"},{"introduced":"0.34"},{"last_affected":"0.34"},{"introduced":"0.35"},{"last_affected":"0.35"},{"introduced":"0.37"},{"last_affected":"0.37"},{"introduced":"0.38"},{"last_affected":"0.38"},{"introduced":"0.39"},{"last_affected":"0.39"},{"introduced":"0.40"},{"last_affected":"0.40"},{"introduced":"0.41"},{"last_affected":"0.41"},{"introduced":"0.50"},{"last_affected":"0.50"},{"introduced":"0.51"},{"last_affected":"0.51"},{"introduced":"0.53"},{"last_affected":"0.53"},{"introduced":"0.54"},{"last_affected":"0.54"},{"introduced":"0.55"},{"last_affected":"0.55"},{"introduced":"0.56"},{"last_affected":"0.56"},{"introduced":"0.60"},{"last_affected":"0.60"},{"introduced":"0.61"},{"last_affected":"0.61"}],"source":"AFFECTED_FIELD"}}],"versions":["0.1","0.11","0.12","0.2","0.20","0.21","0.22","0.23","0.24","0.25","0.26","0.27","0.3","0.30","0.31","0.32","0.33","0.34","0.35","0.37","0.38","0.39","0.4","0.40","0.41","0.5","0.50","0.51","0.53","0.54","0.55","0.56","0.6","0.60","0.61","0.7","v0.61","v0.60","v0.56.3","v0.56.2","v0.56","v0.55.4","v0.55.3","v0.55.2","v0.55.1","v0.55","v0.54","v0.53.2","v0.53","v0.51","v0.50","v0.41","v0.40.3","v0.40.2","v0.40.1","v0.40","v0.39","v0.38","v0.37.3","v0.37.2","v0.37","v0.35.1","v0.35","v0.34.5","v0.34.4","v0.34.2","v0.34.1","v0.34","v0.33.2","v0.33.1","v0.33","v0.32.2","v0.32.1","v0.32","v0.31","v0.30","v0.27","v0.26","v0.25.1","v0.25","v0.24.3","v0.24.2","v0.24.1","v0.24","v0.23","v0.22.2","v0.22.1","v0.22","v0.21","v0.20.6","v0.20.5","v0.20.4","v0.20.3","v0.20.1","v0.20","v0.12","v0.11.0","v0.11","v0.5.2","v0.5.1","v0.5.0","v0.4.2","v0.4.0","v0.3.6","v0.3.5","v0.3.2","v0.3.1","v0.3.0","v0.2.0","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16217.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}