CVE-2026-75419CWE-113

CVE-2026-75419

High · published August 28, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
24.8
In the wild
Unconfirmed
What it is

go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users, resetting passwords, and creating tenants.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00323 · 24.8th percentile
Weakness
CWE-113 · Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
Published
2026-08-28T04:18Z
References (3)
EPSS history
Timeline
  • 02 SEP 03:39Z
    EPSS moved — → 0%
    epss
  • 27 AUG 00:00Z
    go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability
    cvelistv5