Information Disclosure Vulnerability in Guns by Stylefeng
CVE-2026-92600
7.1HIGH
What is CVE-2026-92600?
The Guns application version 8.3.5 is affected by an information disclosure vulnerability that exists within the SysUserController. This issue arises from the omission of the requiredPermission configuration in the /sysUser/detail and /sysUser/page endpoints. Consequently, this flaw permits attackers who possess a valid login token to bypass Role-Based Access Control (RBAC) validation, granting them unauthorized access to sensitive user information. This includes retrieving account names, real names, email addresses, phone numbers, last login IPs, and role assignments for all users within the system, potentially compromising user privacy and security.
Affected Version(s)
Guns 0 <= 8.3.5
