PatchSiren

continew-org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH continew-org CVE published 2026-09-16

CVE-2026-92603

CVE-2026-92603 is an authorization bypass vulnerability in ContiNew Admin through version 4.1.0, allowing authenticated users to delete other users' messages and announcements without ownership validation. This vulnerability enables attackers to supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all recipients' read receipts. Defenders responsible for ContiNew [truncated]