CVE-2026-92601 PUBLISHED

Guns through 8.3.5 Improper Access Control via SysNoticeController

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated users without assigned roles can exploit this to create, edit, delete, publish and retract system-wide notices affecting arbitrary users and departments.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor stylefeng
Product Guns
Versions Default: unaffected
  • affected from 0 to 8.3.5 (incl.)

Credits

  • George Chen reporter

References

Problem Types

  • Missing Authorization CWE