{"id":"CVE-2026-92603","summary":"ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageController","details":"ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all recipients' read receipts without ownership validation.","modified":"2026-09-20T14:16:38.423810Z","published":"2026-09-16T16:03:08.492Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92603.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92603.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92603"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/continew-admin-through-4.1.0-unauthorized-message-deletion-via-usermessagecontroller"},{"type":"REPORT","url":"https://github.com/continew-org/continew-admin/issues/220"},{"type":"FIX","url":"https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296"},{"type":"PACKAGE","url":"https://github.com/continew-org/continew-admin"},{"type":"ARTICLE","url":"https://github.com/continew-org/continew-admin/blob/v4.1.0/continew-system/src/main/java/top/continew/admin/system/controller/UserMessageController.java#L93-L97"},{"type":"ARTICLE","url":"https://github.com/continew-org/continew-admin/blob/v4.1.0/continew-system/src/main/java/top/continew/admin/system/service/impl/MessageServiceImpl.java#L130-L135"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/continew-org/continew-admin","events":[{"introduced":"0"},{"fixed":"e0e3294b3d56c114e2afbc36aac38506fdcd0d0d"},{"fixed":"665ea2c757a3f1246db62fb139fec1aac3cca296"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.1.0"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v4.1.0","v4.0.0","v3.6.0","v3.5.0","v3.4.1","v3.4.0","v3.3.0","v3.2.0","v3.1.0","v3.0.1","v3.0.0","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.0","v2.0.0","v1.3.0","v1.2.0","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92603.json","vanir_signatures_modified":"2026-09-20T14:16:38Z","vanir_signatures":[{"id":"CVE-2026-92603-1a2abd15","signature_type":"Line","signature_version":"v1","source":"https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296","target":{"file":"continew-system/src/main/java/top/continew/admin/system/service/impl/MessageServiceImpl.java"},"deprecated":false,"digest":{"line_hashes":["4642180874318694783276933952382430116","336280497788011365499931964577259959696","203318076733879166757681412809585131210","34733037656125222180295641946108561622","322313994267442027318144021161601565240","48542078375355043803227805996556623022","211268371211893643178332707584028629742","241922877111471011880555707241720906830","280130196188075811756504313575191980960"],"threshold":0.9}},{"id":"CVE-2026-92603-1c0f4bea","signature_type":"Function","signature_version":"v1","source":"https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296","target":{"file":"continew-system/src/main/java/top/continew/admin/system/service/impl/MessageServiceImpl.java","function":"delete"},"deprecated":false,"digest":{"function_hash":"150083657190648099578450129910038897323","length":109}},{"deprecated":false,"digest":{"function_hash":"159598956629495383843090298373507381833","length":109},"id":"CVE-2026-92603-3ccf0ac1","signature_type":"Function","signature_version":"v1","source":"https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296","target":{"file":"continew-system/src/main/java/top/continew/admin/system/controller/UserMessageController.java","function":"delete"}},{"digest":{"line_hashes":["25017628748351618673098487490113105757","259215795951288886795937492918863930867","103381417787514549286999984180985047229","328807060243035345448312334455356994858","22480802384712305562797671743688191079","23654750532302524838336727237656198645","292278449265829943187390759700742783111","161041360402508543551545755694369408576","329497844402168846584041138509448115375","23654750532302524838336727237656198645","290885839337122010169365470014940771565","170310000956715792404109388659540588690"],"threshold":0.9},"id":"CVE-2026-92603-7af02518","signature_type":"Line","signature_version":"v1","source":"https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296","target":{"file":"continew-system/src/main/java/top/continew/admin/system/service/impl/UserServiceImpl.java"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296","target":{"file":"continew-system/src/main/java/top/continew/admin/system/controller/UserMessageController.java"},"deprecated":false,"digest":{"line_hashes":["292083579628044513774413704915038292332","132712657675405296340285637735553511815","150699428380787989117192006912600052181","129928625324038266955329283128888840882"],"threshold":0.9},"id":"CVE-2026-92603-dc8e8dfc","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["141530416666113722973653165721629458394","16214025941404566770304560607825166005"],"threshold":0.9},"id":"CVE-2026-92603-f0d69766","signature_type":"Line","signature_version":"v1","source":"https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296","target":{"file":"continew-system/src/main/java/top/continew/admin/system/service/MessageService.java"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}