PT-2026-93862 · Unknown · Continew Admin

·

CVE-2026-92603

·

Published

2026-09-16

·

Updated

2026-09-18

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ContiNew Admin versions prior to 4.1.1
Description An authorization bypass exists in the personal message delete endpoint. Authenticated users can delete messages and announcements belonging to other users by providing arbitrary message identifiers in the IdsReq parameter. This allows for the removal of any message row and the purging of read receipts for all recipients because the system fails to validate ownership of the messages.
Recommendations Update to a version later than 4.1.0. Restrict access to the personal message delete endpoint to minimize the risk of unauthorized message deletion.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92603

Affected Products

Continew Admin