VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-85607High· 8.8PoC
3w ago

Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/rou…

Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/rou…

▾ Midnightblinkospace · blinkoEPSS 0.69%via NVD
CVE-2026-61688Medium· 6.5PoC
3w ago

SolidInvoice is an open-source invoicing platform

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponen…

▾ TwilightSolidInvoice · SolidInvoiceEPSS 0.35%via NVD
CVE-2026-85781High· 8.7
3w ago

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion…

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.44%via NVD
CVE-2026-85638High· 7.3PoC
3w ago

A weakness has been identified in jofpin trape 2.0

A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit h…

▾ Midnightjofpin · trapeEPSS 0.52%via NVD
CVE-2026-17627Medium· 4.9
3w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.

▾ Sunlitlangflow · langflowEPSS 0.20%via NVD
CVE-2026-85594Critical· 9.8⚖ disputed
3w ago

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from th…

▾ Midnighttraefik · traefikEPSS 0.48%via NVD
CVE-2026-85579Medium· 4.3PoC
3w ago

SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint

SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global und…

▾ Twilightsiyuan-note · siyuanEPSS 0.28%via NVD
CVE-2026-85381Medium· 5.3PoC
3w ago

A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930

A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Home/Controller/ChapterController.c…

▾ Twilightlight0011 · cmsEPSS 0.57%via NVD
CVE-2026-63735High· 8.1
3w ago

SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path

SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path

▾ Twilightsurrealdb · surrealdbEPSS 0.37%via GHSA
CVE-2026-53769Medium· 6.5PoC
3w ago

Avo is a framework to create admin panels for Ruby on Rails apps

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload…

▾ Twilightavo-hq · avoEPSS 0.42%via NVD
CVE-2026-85177Medium· 5.4PoC
3w ago

CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages

CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns includ…

▾ Twilightcrmeb · CRMEBEPSS 0.27%via NVD
CVE-2026-85178High· 7.7PoC
3w ago

Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier

Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owne…

▾ MidnightHelicone · heliconeEPSS 0.41%via NVD
CVE-2026-85378High· 7.3PoC
3w ago

light0011 cms Chapter Controller ChapterController.class.php _initialize authorization

A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/Chapte…

▾ Midnightlight0011 · cmsEPSS 0.52%via CVEORG
CVE-2026-85214High· 8.1PoC
3w ago

vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body

vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, a…

▾ Midnightlenve · vhrEPSS 0.50%via NVD
CVE-2026-85211High· 7.7PoC
3w ago

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying ar…

▾ MidnightHumanSignal · label-studioEPSS 0.41%via NVD
CVE-2026-85182High· 7.5PoC
3w ago

vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller

vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account…

▾ Midnightlenve · vhrEPSS 0.44%via NVD
CVE-2026-85392Medium· 4.3
3w ago

Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplying arbitrary user IDs

Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplying arbitrary user IDs. Attackers can f…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-85389Medium· 6.5
3w ago

Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data

Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers can query task endpoints with arbitrary task UUID…

▾ SunlitWorklenz · worklenzEPSS 0.45%via NVD
CVE-2026-85173Medium· 4.3
3w ago

n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects

n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attac…

▾ Sunlitn8n · n8nEPSS 0.35%via NVD
CVE-2026-75033High· 7.7
3w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user…

▾ Twilightsuse · rancherEPSS 0.34%via NVD
CVE-2026-71404High· 8.7
3w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A us…

▾ Twilightsuse · rancherEPSS 0.42%via NVD
CVE-2026-71403Medium· 6.1
3w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreig…

▾ Sunlitsuse · rancherEPSS 0.37%via NVD
CVE-2026-69857High· 8.5
3w ago

Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.

Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.

▾ Twilightmicrosoft · azure_cosmos_dbEPSS 0.63%via NVD
CVE-2026-85308Medium· 5.3
3w ago

Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.

Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.

▾ SunlitEPSS 0.34%via NVD
CVE-2026-84769Medium· 6.5
3w ago

Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.

Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.

▾ SunlitEPSS 0.27%via NVD
CVE-2026-83711Critical· 10.0
3w ago

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · EntraEPSS 0.81%via NVD
CVE-2026-75035High· 7.7
3w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authent…

▾ Twilightsuse · rancherEPSS 0.34%via NVD
CVE-2026-72802Medium· 5.3
3w ago

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via GHSA
CVE-2026-14199High· 7.1
3w ago

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a del…

▾ Twilightgrafana · grafanaEPSS 0.31%via NVD
CVE-2026-81846Low· 3.5
3w ago

An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0

An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:…

▾ SunlitEPSS 0.27%via NVD
CWE-639 vulnerabilities (CVEs) — page 11 · VulnSea