CVE-2026-92603

Source
https://cve.org/CVERecord?id=CVE-2026-92603
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92603.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92603
Published
2026-09-16T16:03:08Z
Modified
2026-09-20T14:16:38Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageController
Details

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all recipients' read receipts without ownership validation.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-639"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92603.json"
}
References

Affected packages

Git / github.com/continew-org/continew-admin

Affected ranges

Type
GIT
Repo
https://github.com/continew-org/continew-admin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "4.1.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v3.*
v3.0.0
v3.0.1
v3.1.0
v3.2.0
v3.3.0
v3.4.0
v3.4.1
v3.5.0
v3.6.0
v4.*
v4.0.0
v4.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92603.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "4642180874318694783276933952382430116",
                "336280497788011365499931964577259959696",
                "203318076733879166757681412809585131210",
                "34733037656125222180295641946108561622",
                "322313994267442027318144021161601565240",
                "48542078375355043803227805996556623022",
                "211268371211893643178332707584028629742",
                "241922877111471011880555707241720906830",
                "280130196188075811756504313575191980960"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-92603-1a2abd15",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
        "target":  {
            "file":  "continew-system/src/main/java/top/continew/admin/system/service/impl/MessageServiceImpl.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "150083657190648099578450129910038897323",
            "length":  109
        },
        "id":  "CVE-2026-92603-1c0f4bea",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
        "target":  {
            "file":  "continew-system/src/main/java/top/continew/admin/system/service/impl/MessageServiceImpl.java",
            "function":  "delete"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "159598956629495383843090298373507381833",
            "length":  109
        },
        "id":  "CVE-2026-92603-3ccf0ac1",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
        "target":  {
            "file":  "continew-system/src/main/java/top/continew/admin/system/controller/UserMessageController.java",
            "function":  "delete"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "25017628748351618673098487490113105757",
                "259215795951288886795937492918863930867",
                "103381417787514549286999984180985047229",
                "328807060243035345448312334455356994858",
                "22480802384712305562797671743688191079",
                "23654750532302524838336727237656198645",
                "292278449265829943187390759700742783111",
                "161041360402508543551545755694369408576",
                "329497844402168846584041138509448115375",
                "23654750532302524838336727237656198645",
                "290885839337122010169365470014940771565",
                "170310000956715792404109388659540588690"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-92603-7af02518",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
        "target":  {
            "file":  "continew-system/src/main/java/top/continew/admin/system/service/impl/UserServiceImpl.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "292083579628044513774413704915038292332",
                "132712657675405296340285637735553511815",
                "150699428380787989117192006912600052181",
                "129928625324038266955329283128888840882"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-92603-dc8e8dfc",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
        "target":  {
            "file":  "continew-system/src/main/java/top/continew/admin/system/controller/UserMessageController.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "141530416666113722973653165721629458394",
                "16214025941404566770304560607825166005"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-92603-f0d69766",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
        "target":  {
            "file":  "continew-system/src/main/java/top/continew/admin/system/service/MessageService.java"
        }
    }
]
vanir_signatures_modified
"2026-09-20T14:16:38Z"