VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-80354High· 8.1
2w ago

Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposin…

Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposin…

▾ Twilightapache · camelEPSS 0.50%via NVD
CVE-2026-68527Medium· 5.9
2w ago

Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog

Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied i…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.47%via CVEORG
CVE-2026-9225Medium· 6.5
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api…

▾ Sunlitlangflow · langflowEPSS 0.35%via NVD
CVE-2026-84062Medium· 4.3
2w ago

BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key

BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product may be caused.

▾ SunlitD-ZERO CO.,LTD. · BurgerEditorEPSS 0.30%via CVEORG
CVE-2026-82582Medium· 4.3
2w ago

An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.

An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.

▾ SunlitSHIRASAGI Project · SHIRASAGIEPSS 0.31%via NVD
CVE-2026-87997Medium· 4.3PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id…

▾ Twilightopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-86763Low· 3.5
2w ago

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route)

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time,…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.27%via NVD
CVE-2026-87809Medium· 6.5
2w ago

Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints

Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints. Attackers with reader access can retrieve the full rendered content of p…

▾ Sunlitsiyuan-note · siyuanEPSS 0.35%via NVD
CVE-2026-86743Medium· 5.0PoC
2w ago

Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies

Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets repo…

▾ Twilightsnipeitapp · snipe-itEPSS 0.29%via NVD
CVE-2026-86761Medium· 4.3PoC
2w ago

snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks

snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned…

▾ Twilightsnipeitapp · snipe-itEPSS 0.36%via NVD
CVE-2026-87994Medium· 4.3PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the channel branch of chat_completion in backend/open_webui/main.py checked channel write access and channel membership for a …

▾ Twilightopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-59185High· 8.5
2w ago

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

▾ Twilightidentrail · github.com/identrail/identrailvia OSV
CVE-2026-79324High· 7.5
2w ago

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresse…

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresse…

▾ Twilightmageplaza · gdprEPSS 0.56%via NVD
CVE-2026-67403Critical· 9.0
2w ago

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specif…

▾ MidnightSage · Sage AR AutomationEPSS 0.27%via NVD
CVE-2026-85037Medium· 5.3
2w ago

The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price…

The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-13146Low· 3.7
2w ago

The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address t…

The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address t…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-87047Medium· 6.3
2w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.26%via NVD
CVE-2026-87033Medium· 5.4
2w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.29%via NVD
CVE-2026-87025Medium· 5.4
2w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.29%via NVD
CVE-2026-87019Medium· 4.3
2w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.26%via NVD
CVE-2026-47156Critical· 9.3
2w ago

MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator

MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowi…

▾ Midnightmantisbt · mantisbtEPSS 0.69%via CVEORG
CVE-2026-19651High· 7.4
2w ago

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

▾ TwilightIBM · Enterprise Build of QuarkusEPSS 0.26%via NVD
CVE-2026-78462High· 8.8
2w ago

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

▾ Twilightmicrosoft · visual_studio_codeEPSS 0.76%via NVD
CVE-2026-69375Medium· 6.5
2w ago

Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

▾ SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.66%via NVD
CVE-2026-86840Critical· 9.1PoC
2w ago

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying …

▾ AbyssalBitfrost.io · BifrostEPSS 0.42%via NVD
CVE-2026-86725High· 7.1PoC
2w ago

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records.…

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records.…

▾ MidnightWWBN · AVideoEPSS 0.35%via NVD
CVE-2026-86720High· 8.1PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. …

▾ MidnightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-73320Medium· 6.1PoC
2w ago

XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoin…

XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs to the unfurl endpoin…

▾ Twilightxenforo · xenforoEPSS 0.36%via NVD
CVE-2026-81802Medium· 6.5
2w ago

Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

▾ SunlitMagepeople inc. · mage-eventpressEPSS 0.33%via NVD
CVE-2026-53639Medium· 6.3
2w ago

Sylius is an Open Source eCommerce Framework on Symfony

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints lo…

▾ SunlitSylius · SyliusEPSS 0.54%via NVD
CWE-639 vulnerabilities (CVEs) — page 9 · VulnSea