CWE-639
CVEs classified under CWE-639, newest first.
668 CVEsRSS
GHSA-86cx-wwf4-phq4Medium· 6.5OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
GHSA-c8vc-7pv3-g98pHighBudibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
GHSA-rjg6-39jm-rgg4Critical· 9.9@better-auth/scim: account takeover and stale access via SCIM provider-id collision
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
GHSA-h3rm-78g3-j7cpHigh· 7.1@better-auth/stripe: cross-organization billing tampering in organization subscription actions
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
CVE-2026-15630Critical· 9.9PoCA non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
CVE-2026-65013High· 8.8PoCOnlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…
CVE-2026-59259Mediumn8n: External Secrets Permission Bypass via Expression Parser Mismatch
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
CVE-2026-59254Mediumn8n: External Secrets Accessible via Workflow Expressions Outside Credentials
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
CVE-2026-59253Mediumn8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
GHSA-mwq7-vcmc-cm4qHighDuplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
CVE-2026-65016Highn8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
CVE-2026-65316Medium· 6.5xxl-job Cross-Job-Group Log Disclosure via Missing Authorization Check in /joblog/logDetailCat
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to…
CVE-2026-58435Medium· 5.4Gitea LFS Deploy-Key Privilege Escalation
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58432Medium· 5.9Gitea: draft release attachment disclosure via missing web authorization
Gitea: draft release attachment disclosure via missing web authorization
CVE-2026-57886Medium· 5.9Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
CVE-2026-58445Low· 2.7Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-13381High· 8.1VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint
VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and dele…
CVE-2026-61836High· 8.6Directus: Authorization-dependent response served from unsegmented cache key
Directus: Authorization-dependent response served from unsegmented cache key
CVE-2026-16217Medium· 6.3A security vulnerability has been detected in guohongze adminset up to 0.61
A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the a…
CVE-2026-16214Medium· 6.3A vulnerability was identified in geex-arts django-jet up to 1.0.8
A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be…
CVE-2026-16075Medium· 4.3A flaw has been found in AstrBotDevs AstrBot up to 4.25.5
A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. This manipulati…
CVE-2026-15945Medium· 4.3A flaw was found in the group search functionality of the Keycloak server's administrative API
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they…
CVE-2026-53536NoneActivepieces is an open source AI workflow automation platform
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined…
CVE-2026-52869High· 7.1MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-52882MediumMantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
CVE-2026-15637High· 7.5Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credenti…
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credenti…
CVE-2026-15058Low· 3.1Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
CVE-2026-50141HighWoodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
CVE-2026-54052Critical· 9.9n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
CVE-2025-32781Medium· 6.5Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center