Improper Access Control in SysNoticeController of Guns by Stylefeng
CVE-2026-92601
7.1HIGH
What is CVE-2026-92601?
The Guns product version 8.3.5 has an improper access control vulnerability in the SysNoticeController component. This flaw occurs because the requiredPermission is set to false by default and is not properly enforced by any action methods. As a result, authenticated users who do not have assigned roles can exploit this vulnerability to create, edit, delete, publish, and retract system-wide notices. This unauthorized access potentially impacts all users and departments within the system, exposing sensitive functionalities without adequate permissions.
Affected Version(s)
Guns 0 <= 8.3.5
