SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86118

MEDIUM · CVSS 4.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Versions of gonic prior to 0.22.0 are vulnerable due to inadequate validation of administrator privileges in the startScan endpoint, enabling any authenticated user to initiate media library rescans. This flaw can lead to denial of service by allowing attackers to overload system resources through repeated calls to the endpoint. Organizations using gonic in multi-user environments should prioritize patching to mitigate potential disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86118
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%

Original NVD Description

gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.