HIGHVulnerability

CVE-2026-75419

go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users, resetting passwords, and creating tenants.

Properties

severity
HIGH
score
8.8
epss_score
0.00323
cve_id
CVE-2026-75419
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-28T00:18:12.677
last_modified
2026-09-01T21:00:36.830
epss_percentile
0.24891

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75419 — Ninja Signal Threat Intelligence | Ninja Signal