Permission Bypass in bbs-go AdminMiddleware Related to User Dashboard Access
CVE-2026-103396
5.3MEDIUM
What is CVE-2026-103396?
The bbs-go application versions prior to 4.4.6 are susceptible to a permission bypass vulnerability within the AdminMiddleware authorization logic. Specifically, the dashboard.user.view permission can erroneously match the /api/admin/user/synccount endpoint, allowing authenticated users with only view permissions to execute costly full-table user recount operations and cache invalidations. This behavior can be exploited to create a denial of service by initiating repeated concurrent database transactions, thereby overwhelming the system.
Affected Version(s)
bbs-go 0 <= 4.4.6
