HIGHVulnerability
CVE-2026-75419
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users, resetting passwords, and creating tenants.
Properties
- severity
- HIGH
- score
- 8.8
- epss_score
- 0.00323
- cve_id
- CVE-2026-75419
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-08-28T00:18:12.677
- last_modified
- 2026-09-01T21:00:36.830
- epss_percentile
- 0.24891
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph