MEDIUM
CVE-2026-92600
CVSS
6.5
Description
Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC validation for authenticated users. Attackers with any valid login token can retrieve sensitive user information including account names, real names, email addresses, phone numbers, last login IPs, and role assignments for all users in the system.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.32%
Probability of exploitation in next 30 days
24.8th percentile
References
https://github.com/stylefeng/Guns
https://github.com/stylefeng/Guns/blob/2a12947733945d5c06197d99ecaa77d7f2b0aeba/src/main/java/cn/stylefeng/guns/core/security/TokenAndPermissionInterceptor.java#L110-L119
https://github.com/stylefeng/Guns/issues/118
https://repo1.maven.org/maven2/com/javaguns/roses/system-business-hr/8.3.5/system-business-hr-8.3.5-sources.jar
https://www.vulncheck.com/advisories/guns-through-8.3.5-information-disclosure-via-missing-permission-check
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.