CVE-2026-92992 Details
Description
A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The identifier of the patch is 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde. Applying a patch is the recommended action to fix this issue. The whitelist bypass is one-token wide. Any compound command containing curl, wget or sed auto-runs without approval; approval is granted by the same session user (self-approval). This issue got fixed with a silent patch.
A vulnerability allowing missing authorization in the AI Assistant component has been identified in Dromara Mayfly-Go versions through 1.11.5. The issue arises from an unknown function in the file server/internal/ai/api/ai.go, leading to unauthorized access and actions. This vulnerability can be exploited remotely, allowing authenticated users to execute commands on unauthorized machines or read and modify databases without proper authorization. The vulnerability has been publicly disclosed and exploited.
Users are advised to update to the latest version of Dromara Mayfly-Go, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/xufengnian/b95662ba0d8881cfc5ba0bb99cbfc086 | CISA-ADP | BundleExploitRemedy |
| https://gist.github.com/xufengnian/b95662ba0d8881cfc5ba0bb99cbfc086 | [email protected] | BundleExploitRemedy |
| https://github.com/dromara/mayfly-go/ | [email protected] | ProductVendor |
| https://github.com/dromara/mayfly-go/commit/74bcb926eb4f5f94e7681144d7bf2168a0ec7cde | [email protected] | Source CodeVendor |
| https://github.com/dromara/mayfly-go/pull/129 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-92992 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/942253 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/406446 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/406446/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dromara mayfly-go | >= 1.11.0, <= 1.11.5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 17, 2026 | New CVE Received | [email protected] |
Volerion