CVE-2026-86118

medium

Description

gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.

References

https://www.vulncheck.com/advisories/gonic-before-0.22.0-missing-administrator-check-on-the-subsonic-startscan-endpoint

https://github.com/sentriz/gonic/security/advisories/GHSA-453r-pgfw-h3pq

https://github.com/sentriz/gonic/releases/tag/v0.22.0

https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/handlers_common.go

https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/ctrl.go

https://github.com/sentriz/gonic

Details

Source: Mitre, NVD

Published: 2026-09-05

Updated: 2026-09-05

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium