Improper Access Control in SysNoticeController of Guns by Stylefeng
CVE-2026-92601

7.1HIGH

Key Information:

Vendor

Stylefeng

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92601?

The Guns product version 8.3.5 has an improper access control vulnerability in the SysNoticeController component. This flaw occurs because the requiredPermission is set to false by default and is not properly enforced by any action methods. As a result, authenticated users who do not have assigned roles can exploit this vulnerability to create, edit, delete, publish, and retract system-wide notices. This unauthorized access potentially impacts all users and departments within the system, exposing sensitive functionalities without adequate permissions.

Affected Version(s)

Guns 0 <= 8.3.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.