ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all recipients' read receipts without ownership validation.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-639"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92603.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.1.0"
}
],
"source": [
"DESCRIPTION",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92603.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"4642180874318694783276933952382430116",
"336280497788011365499931964577259959696",
"203318076733879166757681412809585131210",
"34733037656125222180295641946108561622",
"322313994267442027318144021161601565240",
"48542078375355043803227805996556623022",
"211268371211893643178332707584028629742",
"241922877111471011880555707241720906830",
"280130196188075811756504313575191980960"
],
"threshold": 0.9
},
"id": "CVE-2026-92603-1a2abd15",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
"target": {
"file": "continew-system/src/main/java/top/continew/admin/system/service/impl/MessageServiceImpl.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "150083657190648099578450129910038897323",
"length": 109
},
"id": "CVE-2026-92603-1c0f4bea",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
"target": {
"file": "continew-system/src/main/java/top/continew/admin/system/service/impl/MessageServiceImpl.java",
"function": "delete"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "159598956629495383843090298373507381833",
"length": 109
},
"id": "CVE-2026-92603-3ccf0ac1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
"target": {
"file": "continew-system/src/main/java/top/continew/admin/system/controller/UserMessageController.java",
"function": "delete"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"25017628748351618673098487490113105757",
"259215795951288886795937492918863930867",
"103381417787514549286999984180985047229",
"328807060243035345448312334455356994858",
"22480802384712305562797671743688191079",
"23654750532302524838336727237656198645",
"292278449265829943187390759700742783111",
"161041360402508543551545755694369408576",
"329497844402168846584041138509448115375",
"23654750532302524838336727237656198645",
"290885839337122010169365470014940771565",
"170310000956715792404109388659540588690"
],
"threshold": 0.9
},
"id": "CVE-2026-92603-7af02518",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
"target": {
"file": "continew-system/src/main/java/top/continew/admin/system/service/impl/UserServiceImpl.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"292083579628044513774413704915038292332",
"132712657675405296340285637735553511815",
"150699428380787989117192006912600052181",
"129928625324038266955329283128888840882"
],
"threshold": 0.9
},
"id": "CVE-2026-92603-dc8e8dfc",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
"target": {
"file": "continew-system/src/main/java/top/continew/admin/system/controller/UserMessageController.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"141530416666113722973653165721629458394",
"16214025941404566770304560607825166005"
],
"threshold": 0.9
},
"id": "CVE-2026-92603-f0d69766",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/continew-org/continew-admin/commit/665ea2c757a3f1246db62fb139fec1aac3cca296",
"target": {
"file": "continew-system/src/main/java/top/continew/admin/system/service/MessageService.java"
}
}
]
"2026-09-20T14:16:38Z"