GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92793.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.2.26"
},
{
"fixed": "1.2.26"
}
],
"source": [
"AFFECTED_FIELD",
"DESCRIPTION"
]
}