VulnSea

CWE-285

CVEs classified under CWE-285, newest first.

247 CVEsRSS

GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

▾ Twilightgeolens · geolensvia GHSA
CVE-2026-55519Medium· 5.4
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in …

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.37%via NVD
CVE-2026-48744Medium· 6.5
1mo ago

Saleor is an e-commerce platform

Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-70923Medium· 6.1
1mo ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-55166Critical· 9.9
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend req…

▾ Midnightlemur · lemurEPSS 0.29%via NVD
GHSA-m5w8-4gq2-6f8xCritical· 10.0
1mo ago

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

▾ Midnightvm2 · vm2via GHSA
CVE-2026-73421None
1mo ago

NextAuth.js provides authentication for Next.js

NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.…

▾ SunlitEPSS 0.64%via NVD
CVE-2026-73644Critical· 9.6
1mo ago

OpenDJ is an LDAPv3 compliant directory service

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privil…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-72907Medium· 6.5
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, all…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-47663None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller w…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-59118Critical· 9.3
1mo ago

Copilot Cowork Elevation of Privilege Vulnerability

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Copilot CoworkEPSS 0.72%via CVEORG
GHSA-p8x7-9vfw-p7vcHigh
1mo ago

Craft CMS: Arbitrary user password reset leading to administrator account takeover

Craft CMS: Arbitrary user password reset leading to administrator account takeover

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-45415Medium· 6.0
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorizatio…

▾ Sunlitdecidim-verifications · decidim-verificationsEPSS 0.43%via NVD
CVE-2026-70472High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without …

▾ Twilightflowiseai · flowiseEPSS 0.52%via NVD
CVE-2026-48115None
1mo ago

Misskey is an open source, federated social media platform

Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API where insufficient permission checks allo…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-67332Medium· 6.4
1mo ago

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens who…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-14538High· 7.7
1mo ago

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation che…

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation che…

▾ Twilightgoogle · mcp_toolbox_for_databasesEPSS 0.20%via NVD
CVE-2026-41187Medium· 6.5
1mo ago

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requ…

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requ…

▾ Sunlittigera · calicoEPSS 0.39%via NVD
CVE-2026-43983High
2mo ago

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

▾ Twilightpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.36%via GHSA
CVE-2026-17434Medium· 6.3
2mo ago

A flaw has been found in nanocoai NanoClaw up to 2.0.64

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-17433Medium· 5.3
2mo ago

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in im…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-62835Critical· 9.3
2mo ago

Azure Portal Information Disclosure Vulnerability

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

▾ MidnightMicrosoft · Azure PortalEPSS 0.97%via CVEORG
CVE-2026-56160Critical· 9.1
2mo ago

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_red_hat_openshiftEPSS 0.79%via NVD
GHSA-pvcr-8mvp-w8qrHigh· 7.7
2mo ago

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-p279-2cqp-84jgCritical· 9.6
2mo ago

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

▾ Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-server-legacyvia GHSA
CVE-2026-59226Low· 3.1
2mo ago

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

▾ Sunlitopen-webui · open-webuiEPSS 0.53%via GHSA
GHSA-8fpg-xm3f-6cx3Critical
2mo ago

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

▾ Midnightnext-auth · next-authvia GHSA
CVE-2026-64642High
2mo ago

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

▾ Twilightnext · nextEPSS 0.64%via GHSA
CVE-2026-58424High· 8.9PoC
2mo ago

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-53515High· 7.1
2mo ago

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

▾ Twilightbetter-auth · @better-auth/ssoEPSS 0.43%via GHSA
CWE-285 vulnerabilities (CVEs) — page 5 · VulnSea