PT-2026-86389 · Gonic · Gonic

·

CVE-2026-86118

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions gonic versions prior to 0.22.0
Description Authenticated users can trigger media library rescans because the software fails to validate administrator privileges at the 'startScan' endpoint. By repeatedly calling this endpoint, an attacker can force CPU and I/O-intensive filesystem operations, leading to a denial of service on multi-user instances.
Recommendations Update to version 0.22.0 or later. As a temporary workaround, restrict access to the 'startScan' endpoint to prevent unauthorized users from triggering rescans.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86118
GHSA-453R-PGFW-H3PQ

Affected Products

Gonic