VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

670 CVEsRSS

GHSA-h3m5-97jq-qjrfCritical· 9.6
3mo ago

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

▾ Midnightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-53863Medium
3mo ago

OpenClaw: Tool group policy callers could accept unvalidated group IDs

OpenClaw: Tool group policy callers could accept unvalidated group IDs

▾ Sunlitopenclaw · openclawEPSS 0.29%via GHSA
CVE-2026-55670Low
3mo ago

ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers

ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.36%via GHSA
GHSA-2fjj-qqg8-fg7xMedium· 4.3
3mo ago

praisonai-platform: Authorization Bypass Through User-Controlled Key

praisonai-platform: Authorization Bypass Through User-Controlled Key

▾ Sunlitpraisonai-platform · praisonai-platformvia GHSA
CVE-2026-54683Medium· 6.5
3mo ago

NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)

NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)

▾ Sunlitnl-portal · nl.nl-portal:documenten-apivia GHSA
GHSA-hjwc-26pj-v3pmHigh
3mo ago

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

▾ Twilightagenticmail · @agenticmail/apivia GHSA
CVE-2026-55198Medium· 6.5PoC
3mo ago

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails …

▾ Twilightnesquena · hermes-webuiEPSS 0.47%via NVD
CVE-2026-55197Medium· 6.5PoC
3mo ago

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by direc…

▾ Twilightnesquena · hermes-webuiEPSS 0.47%via NVD
CVE-2026-54006Medium· 4.3
3mo ago

Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar

Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-54009Medium· 6.5
3mo ago

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field

▾ Sunlitopen-webui · open-webuiEPSS 0.38%via GHSA
CVE-2026-54010High· 8.3
3mo ago

Open WebUI: Forged chat-file link allows cross-user file read and deletion

Open WebUI: Forged chat-file link allows cross-user file read and deletion

▾ Twilightopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-54015Medium· 6.4
3mo ago

Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion

Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion

▾ Sunlitopen-webui · open-webuiEPSS 0.27%via GHSA
CVE-2026-54324Medium· 6.5
3mo ago

Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join

Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join

▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.46%via GHSA
CVE-2026-55518Critical· 9.6
3mo ago

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

▾ Midnightavo · avoEPSS 0.45%via GHSA
CVE-2026-33760High· 8.8
3mo ago

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

▾ Twilightlangflow · langflowEPSS 0.50%via GHSA
CVE-2026-54322High· 7.7
3mo ago

Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles

Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles

▾ Twilightdaytonaio · github.com/daytonaio/daytonaEPSS 0.30%via GHSA
GHSA-8wmm-344f-mpjgMedium· 7.1
3mo ago

Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs

Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-48599High· 7.6PoC
3mo ago

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…

▾ Midnightelixir-grpc · grpcEPSS 0.34%via NVD
CVE-2026-54097High
3mo ago

File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix

File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix

▾ Twilightfilebrowser · github.com/filebrowser/filebrowserEPSS 0.45%via GHSA
CVE-2026-48067Medium· 6.5
3mo ago

Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields

Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields

▾ Sunlitfilament · filament/tablesEPSS 0.30%via GHSA
CVE-2026-47068Low
3mo ago

PhoenixStorybook has cross-session PubSub topic injection via URL parameter

PhoenixStorybook has cross-session PubSub topic injection via URL parameter

▾ Sunlitphoenix_storybook · phoenix_storybookEPSS 0.53%via GHSA
CVE-2026-45810Medium· 6.8
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticated users with access to any file commen…

▾ Sunlitnextcloud · nextcloud_serverEPSS 0.44%via NVD
CVE-2026-42999High· 8.3⚖ disputed
4mo ago

openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection (CVE-2026-429…

A flaw was found in OpenStack Keystone. This vulnerability allows an authenticated user to bypass Role-Based Access Control (RBAC) checks by injecting arbitrary policy target attributes into the request body. This enables the user to perfo…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.42%via CSAF
CVE-2026-35430High· 8.8
4mo ago

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · azure_privileged_identity_managementEPSS 0.78%via NVD
CVE-2026-7886Medium· 4.3
4mo ago

Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation controllers accept user-supplied file …

Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation controllers accept user-supplied file …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.47%via NVD
CVE-2026-47101High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified route…

▾ Midnightlitellm · litellmEPSS 1.3%via NVD
CVE-2026-9087Medium· 6.4
4mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume i…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-44283Medium· 4.3⚖ disputed
4mo ago

etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access (CVE-2026-44283)

A flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.27%via CSAF
CVE-2026-41950Medium· 6.5
4mo ago

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files …

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files …

▾ SunlitEPSS 0.47%via NVD
CVE-2026-28747High· 7.1
5mo ago

A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.

A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.

▾ TwilightEPSS 0.28%via NVD
CWE-639 vulnerabilities (CVEs) — page 21 · VulnSea