---
id: CVE-2026-92600
title: >-
  Guns through 8.3.5 contains an information disclosure vulnerability in
  SysUserController where /sysUser/detail and /sysUser/page endpoints omit
  requiredPermission configuration, causing the permission interceptor to skip
  RBAC validation …
summary: >-
  Guns through 8.3.5 contains an information disclosure vulnerability in
  SysUserController where /sysUser/detail and /sysUser/page endpoints omit
  requiredPermission configuration, causing the permission interceptor to skip
  RBAC validation …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
vendor: stylefeng
product: Guns
affected:
  - Guns <= 8.3.5
published: '2026-09-16'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:48.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92600'
references:
  - url: 'https://github.com/stylefeng/Guns'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/stylefeng/Guns/blob/2a12947733945d5c06197d99ecaa77d7f2b0aeba/src/main/java/cn/stylefeng/guns/core/security/TokenAndPermissionInterceptor.java#L110-L119
    label: disclosure@vulncheck.com
  - url: 'https://github.com/stylefeng/Guns/issues/118'
    label: disclosure@vulncheck.com
  - url: >-
      https://repo1.maven.org/maven2/com/javaguns/roses/system-business-hr/8.3.5/system-business-hr-8.3.5-sources.jar
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/guns-through-8.3.5-information-disclosure-via-missing-permission-check
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00422
epssPercentile: 0.33913
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T19:16:44.006359Z'
ingestedAt: '2026-09-16T16:59:56.621Z'
---

## Overview

Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC validation for authenticated users. Attackers with any valid login token can retrieve sensitive user information including account names, real names, email addresses, phone numbers, last login IPs, and role assignments for all users in the system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
