{"id":"CVE-2026-92793","summary":"GoAdmin through 1.2.26 Authorization Bypass via Query Parameter","details":"GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state.","modified":"2026-09-19T03:31:04.318839824Z","published":"2026-09-16T20:32:48.293Z","database_specific":{"cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92793.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92793.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92793"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/goadmin-through-1.2.26-authorization-bypass-via-query-parameter"},{"type":"REPORT","url":"https://github.com/GoAdminGroup/go-admin/issues/690"},{"type":"PACKAGE","url":"https://github.com/GoAdminGroup/go-admin"},{"type":"ARTICLE","url":"https://github.com/GoAdminGroup/go-admin/blob/v1.2.26/modules/auth/middleware.go#L177"},{"type":"ARTICLE","url":"https://github.com/GoAdminGroup/go-admin/blob/v1.2.26/plugins/admin/models/user.go#L129-L133"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/goadmingroup/go-admin","events":[{"introduced":"0"},{"fixed":"da3ce351e5b7256e3d2745d8f11067d738145182"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.2.26"},{"fixed":"1.2.26"}]}}],"versions":["v1.2.25","v1.2.24","v1.2.23","v1.2.22","v1.2.21","v1.2.20","v1.2.19","v1.2.18","v1.2.17","v1.2.16","v1.2.15","v1.2.14","v1.2.13","v1.2.12","v1.2.11","v1.2.10","v1.2.9","v1.2.8","v1.2.7","v1.2.6","v1.2.5","v1.2.4","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.9","v1.1.8","v1.1.7","v1.1.6","v1.1.5","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.10","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0","v1.0.0-beta.1","v1.0.0-beta","v1.0.0-alpha.2","v1.0.0-alpha.1","v1.0.0-alpha","v0.6.0","v0.5.1","v0.5.0","v0.4.2","v0.4.1","v0.4.0","v0.3.1","v0.3.0","v0.2.6","v0.2.5","v0.2.4","v0.2.3","v0.2.2","v0.2.1","v0.2.0","v0.1.2","v0.1.1","v0.1.0","v0.0.15","v0.0.14","v0.0.13","v0.0.12","v0.0.11","v0.0.9-20190910012351-8a420f7b638d","v0.0.9","v0.0.10","v0.0.8","v0.0.7","v0.0.6","v0.0.5","0.0.9","0.0.8","0.0.7","0.0.6","0.0.5","v0.0.4","0.0.4","0.0.3","v0.0.2","0.0.2","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92793.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}