{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agoadmingoadmin/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:goadmin:goadmin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92793"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GoAdmin (\u003c= 1.2.26)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["GoAdmin"],"content_html":"\u003cp\u003eGoAdmin versions through 1.2.26 contain an authorization flaw in the handling of the logout URL pattern. The application fails to properly anchor this pattern during permission verification, which creates a vulnerability allowing authenticated users to bypass intended access controls. By appending a specific query parameter string containing the admin prefix followed by /logout, an attacker can trick the application into incorrectly validating their session against administrative endpoints. This flaw allows low-privileged users to reach administrative functionality that should be restricted to authorized personnel. Successful exploitation results in the ability to read sensitive data or modify the application's internal state. This vulnerability is significant because it provides an entry point for lateral movement and privilege escalation within the web application environment, and organizations utilizing GoAdmin for critical data management are at risk of unauthorized administrative control.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to organizations using GoAdmin to manage internal applications or databases, as it enables unauthorized administrative actions. Attackers can leverage this bypass to perform data exfiltration, modify system configurations, or alter sensitive records. The potential damage includes loss of data confidentiality and integrity, and full compromise of the application's administrative layer.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update of GoAdmin installations. Monitor web access logs for unusual patterns involving the admin prefix and /logout strings.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of GoAdmin to a version beyond 1.2.26 as soon as a patch becomes available.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous requests where the admin prefix appears in conjunction with unexpected query parameters or paths mimicking the logout sequence.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:57:25Z","date_published":"2026-09-16T21:57:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-goadmin-auth-bypass/","summary":"GoAdmin versions through 1.2.26 are vulnerable to an authentication bypass where attackers can manipulate URL pathing to access restricted administrative endpoints.","title":"Authentication Bypass Vulnerability in GoAdmin","url":"https://feed.craftedsignal.io/briefs/2026-09-goadmin-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:goadmin:goadmin:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}