MEDIUM 5.3 NVD

CVE-2026-86118

gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library resca

gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.

References

Published: 2026-09-05 · Source: NVD · Feed updated: 2026-09-05
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-05 via NVD.
vulnfeed aggregates 10223 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.