CVE-2026-84430 Details
Description
A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upgrading the affected component is advised.
A mass assignment vulnerability allowing privilege escalation has been identified in GouGuOA versions through 5.10.0. The issue resides in the 'edit_personal' endpoint, specifically within the 'app/home/controller/Index.php' file. The vulnerability arises because the endpoint processes user-supplied parameters without proper validation, enabling an authenticated attacker to manipulate object attributes dynamically. This exploitation can be performed remotely and has been publicly disclosed.
Users are advised to upgrade to GouGuOA version 6.0.3, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 2, 2026CISA-ADP
Assessed Sep 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitee.com/gouguopen/office/releases/tag/v6.0.3 | [email protected] | Release NotesVendor |
| https://github.com/Angoddess/CVE/blob/main/README.md | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-84430 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/884061 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/397797 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/397797/cti | [email protected] | AdvisoryContent Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-913 | Improper Control of Dynamically-Managed Code Resources | [email protected] |
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GouGuOA | <= 5.10.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | CVE Modified | CISA-ADP |
| Sep 2, 2026 | New CVE Received | [email protected] |
Volerion