---
id: CVE-2026-86118
title: >-
  gonic versions before 0.22.0 fail to validate administrator privileges in the
  startScan endpoint, allowing any authenticated user to trigger media library
  rescans
summary: >-
  gonic versions before 0.22.0 fail to validate administrator privileges in the
  startScan endpoint, allowing any authenticated user to trigger media library
  rescans. Attackers can repeatedly call the startScan endpoint to force CPU and
  I/O…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-862
vendor: sentriz
product: gonic
affected:
  - gonic < 0.22.0
published: '2026-09-05'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T13:42:47.043'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86118'
references:
  - url: 'https://github.com/sentriz/gonic'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/ctrl.go'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/handlers_common.go
    label: disclosure@vulncheck.com
  - url: 'https://github.com/sentriz/gonic/releases/tag/v0.22.0'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/sentriz/gonic/security/advisories/GHSA-453r-pgfw-h3pq'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/gonic-before-0.22.0-missing-administrator-check-on-the-subsonic-startscan-endpoint
    label: disclosure@vulncheck.com
  - url: 'https://github.com/sentriz/gonic/security/advisories/GHSA-453r-pgfw-h3pq'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00473
epssPercentile: 0.38206
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T13:06:32.894121Z'
ingestedAt: '2026-09-06T07:51:56.047Z'
---

## Overview

gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
