CVE-2026-92603: ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageController
ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all recipients' read receipts without ownership validation.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated ContiNew Admin user can exploit it. The attacker does not need elevated privileges or user interaction.
What access or input does an attacker need?
The attacker needs a valid authenticated session and the ability to submit arbitrary message identifiers through the IdsReq parameter of the personal message deletion endpoint. They can target messages and announcements belonging to other users.
What is the impact of a successful attack?
An attacker can delete arbitrary message rows and purge read receipts for all recipients. The provided information indicates an integrity impact, not disclosure or service availability impact.
Which versions are known to be affected?
ContiNew Admin through version 4.1.0 is identified as affected. No fixed version is provided in the available data.