CWE-285
CVEs classified under CWE-285, newest first.
247 CVEsRSS
CVE-2026-12771Medium· 5.0LiteLLM: M2M JWT Handler Has Improper Authorization
LiteLLM: M2M JWT Handler Has Improper Authorization
GHSA-rh39-9c67-59mhHigh· 8.1PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
CVE-2026-54683Medium· 6.5NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
CVE-2026-53851Medium· 5.3OpenClaw: Slack reaction events could ignore reaction notification settings
OpenClaw: Slack reaction events could ignore reaction notification settings
CVE-2026-20190High· 7.5A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An a…
CVE-2026-54012High· 7.1Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVE-2026-48089HighDevGuard has improper authorization on public assets
DevGuard has improper authorization on public assets
CVE-2026-49397Medium· 5.3Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVE-2026-42902High· 7.8Microsoft PowerToys Elevation of Privilege Vulnerability
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
CVE-2026-45490High· 7.8.NET SDK Elevation of Privilege Vulnerability
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-47298High· 8.0Microsoft SharePoint Server Remote Code Execution Vulnerability
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-45503High· 8.1Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
GHSA-7qjx-gp9h-65qjHigh· 8.7Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
CVE-2026-47726Highnebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
CVE-2026-48579Critical· 9.1Microsoft Exchange Online Information Disclosure Vulnerability
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
CVE-2026-47740High· 8.1Shopper is a Headless e-commerce Admin Panel
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate or…
CVE-2026-34656Medium· 4.3Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this …
CVE-2026-8241Medium· 5.3A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03
A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of the component RMI Interface. Such manipulation leads to improper authorization. The atta…
CVE-2026-27912High· 8.0PoCWindows Kerberos Elevation of Privilege Vulnerability
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
CVE-2026-5529Medium· 4.3A vulnerability was detected in Dromara lamp-cloud up to 5.8.1
A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorizatio…
CVE-2017-20238High· 7.1Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mec…
Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mec…
CVE-2026-33105Critical· 10.0Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-32213Critical· 10.0Azure AI Foundry Elevation of Privilege Vulnerability
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-34738Medium· 4.3WWBN AVideo is an open source video platform
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "acti…
CVE-2026-32615Medium· 5.4Discourse is an open-source discussion platform
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, category group moderators could perform privileged actions on …
CVE-2026-4818Medium· 6.8In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
CVE-2026-33186Critical· 9.1PoCgRPC-Go is the Go language implementation of gRPC
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…
CVE-2026-2015Medium· 6.3PoCA weakness has been identified in Portabilis i-Educar up to 2.10
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead …
CVE-2025-66301Critical· 9.6PoCGrav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the …
CVE-2025-13806High· 7.3A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT
A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthMo…