HIGH
continew-org
CVE published 2026-09-16
CVE-2026-92603
CVE-2026-92603 is an authorization bypass vulnerability in ContiNew Admin through version 4.1.0, allowing authenticated users to delete other users' messages and announcements without ownership validation. This vulnerability enables attackers to supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all recipients' read receipts. Defenders responsible for ContiNew [truncated]