CVE-2026-103396: bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount
bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the synccount endpoint to trigger expensive full-table user recounts and cache invalidations, causing denial of service through repeated concurrent database operations.
Affected Software
Event History
Frequently Asked Questions
Can this be exploited without an account?
No. Exploitation requires an authenticated user with low privileges; a user granted only the dashboard.user.view permission is sufficient.
Which deployments should be considered affected?
bbs-go versions through 4.4.6 are affected where users can authenticate with the read-only dashboard.user.view permission.
What is the expected impact of successful exploitation?
Repeated concurrent requests can trigger full-table user recounts and cache invalidations, consuming database resources and causing denial of service. The provided scoring indicates no confidentiality or integrity impact.