VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1329 CVEsRSS

CVE-2026-92589Medium· 4.3
1w ago

Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint

Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries)…

▾ Sunlitcraftcms · cmsEPSS 0.26%via NVD
CVE-2026-61592High· 7.4
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated us…

▾ Twilightdjust-org · djustEPSS 0.39%via NVD
CVE-2026-61594Critical· 9.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()…

▾ Midnightdjust-org · djustEPSS 0.48%via NVD
CVE-2026-61596High· 7.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the…

▾ Twilightdjust-org · djustEPSS 0.33%via NVD
CVE-2026-92753High· 7.1PoC
1w ago

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modif…

▾ MidnightPatrowl · PatrowlManagerEPSS 0.38%via NVD
CVE-2026-92750Medium· 6.5
1w ago

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to. Attackers can query the GET /api/v1/i…

▾ Sunlitharness · harnessEPSS 0.28%via NVD
CVE-2026-92761High· 8.8PoC
1w ago

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH ke…

▾ Midnightretspen · webvirtcloudEPSS 0.61%via NVD
CVE-2026-92754Medium· 4.3PoC
1w ago

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all use…

▾ TwilightPatrowl · PatrowlManagerEPSS 0.34%via NVD
CVE-2026-92763High· 8.1PoC
1w ago

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security…

▾ Midnightrundeck · rundeckEPSS 0.51%via NVD
CVE-2026-92762High· 8.8PoC
1w ago

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to inv…

▾ Midnightpelican · panelEPSS 0.65%via NVD
CVE-2026-92780High· 8.8PoC
1w ago

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator acc…

▾ Midnightdidi · KnowStreamingEPSS 0.52%via NVD
CVE-2026-92772High· 7.1PoC
1w ago

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary prope…

▾ MidnightLeantime · leantimeEPSS 0.53%via NVD
CVE-2026-92783High· 8.1PoC
1w ago

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legiti…

▾ Midnightyeti-platform · yetiEPSS 0.50%via NVD
CVE-2026-92794High· 7.5
1w ago

OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled

OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete documen…

▾ TwilightOpenSignLabs · OpenSignEPSS 0.59%via NVD
CVE-2026-92802Medium· 4.3
1w ago

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using t…

▾ Sunlitkanbn · kanEPSS 0.37%via NVD
CVE-2026-92803Medium· 5.3PoC
1w ago

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without auth…

▾ TwilightLibreTranslate · LibreTranslateEPSS 0.53%via NVD
CVE-2026-86089High· 7.1⚖ disputed
1w ago

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods ag…

▾ Twilightapache · nifiEPSS 0.44%via NVD
CVE-2026-81866Medium· 4.3⚖ disputed
1w ago

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Conn…

▾ Sunlitapache · nifiEPSS 0.56%via NVD
CVE-2026-82561Medium· 6.5
1w ago

Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase…

Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase…

▾ Sunlitapache · nifiEPSS 0.48%via NVD
CVE-2026-87026Low· 3.8
1w ago

Tanium addressed an improper access controls vulnerability in Threat Response.

Tanium addressed an improper access controls vulnerability in Threat Response.

▾ SunlitTanium · Threat ResponseEPSS 0.26%via NVD
CVE-2026-92729High· 8.2PoC
1w ago

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including …

▾ MidnightSigNoz · signozEPSS 0.58%via NVD
CVE-2026-18120Medium· 5.9
1w ago

Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the normal dashboard and CSV Export flow

Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the normal dashboard and CSV Export flow. An unauthenticate…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.27%via NVD
CVE-2026-92601Medium· 6.5PoC
1w ago

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated users without assigned roles can exploit th…

▾ Twilightstylefeng · GunsEPSS 0.39%via NVD
CVE-2026-92600Medium· 6.5
1w ago

Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC validation …

Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC validation …

▾ Sunlitstylefeng · GunsEPSS 0.42%via NVD
CVE-2026-87031Low· 2.7
1w ago

n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account

n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. As a result, any …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.34%via NVD
CVE-2026-87028Medium· 6.5
1w ago

Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authorized to edit, and did not enforce page-view permission befo…

Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authorized to edit, and did not enforce page-view permission befo…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.38%via NVD
CVE-2026-92402Medium· 6.3
1w ago

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.UserController. The …

▾ SunlitChangeWeDer · crmEPSS 0.37%via NVD
CVE-2026-20324Critical· 9.9
1w ago

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exis…

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exis…

▾ MidnightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.45%via NVD
CVE-2026-17526High· 7.2
1w ago

Keycloak is an open-source identity and access management solution

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative contr…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.45%via NVD
CVE-2026-61595High· 7.7
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `thread…

▾ Twilightdjust · djustEPSS 0.39%via NVD
CWE-862 vulnerabilities (CVEs) — page 10 · VulnSea