VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1331 CVEsRSS

CVE-2026-87441Medium· 6.5
2w ago

Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension

Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-87493Medium· 6.5
2w ago

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87431High· 7.5
2w ago

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-87605Medium· 5.3⚖ disputed
2w ago

Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially obtain sensitive information via a crafted HTML …

Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially obtain sensitive information via a crafted HTML …

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87543Medium· 4.3
2w ago

Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-87522Medium· 6.5⚖ disputed
2w ago

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium securi…

▾ Sunlitgoogle · chromeEPSS 0.28%via NVD
CVE-2026-87511Medium· 4.3
2w ago

Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension

Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-87429Medium· 6.5
2w ago

Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page

Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: …

▾ Sunlitgoogle · chromeEPSS 0.29%via NVD
CVE-2026-87631Medium· 6.5⚖ disputed
2w ago

Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page

Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.31%via NVD
CVE-2026-86994Medium· 4.3
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, de…

▾ Sunlitn8n · n8nEPSS 0.34%via NVD
CVE-2026-86993Medium· 4.9
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership chec…

▾ Sunlitn8n · n8nEPSS 0.46%via NVD
CVE-2026-86085Medium· 4.9
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. …

▾ Sunlitn8n · n8nEPSS 0.44%via NVD
CVE-2026-86077Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous f…

▾ Sunlitn8n · n8nEPSS 0.43%via NVD
CVE-2026-81904Medium· 6.3
2w ago

Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block

Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration valu…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.46%via NVD
CVE-2026-86996Medium· 5.4
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a too…

▾ Sunlitn8n · n8nEPSS 0.29%via NVD
CVE-2026-86819High· 7.1
2w ago

Waves Central for macOS contains a local privilege escalation in the privileged helper service

Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than …

▾ TwilightWaves Audio Ltd. · Waves CentralEPSS 0.10%via NVD
CVE-2026-84869Critical· 9.9CISA KEVPoC
2w ago

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

▾ Hadalconnectwise · screenconnectEPSS 0.92%via NVD
CVE-2026-0054Low· 3.3
2w ago

In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check

In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges neede…

▾ Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-28611High· 7.8
2w ago

In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check

In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.…

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-28582Low· 3.3
2w ago

In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of device credentials due to a missing permission check

In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of device credentials due to a missing permission check. This could lead to local information disclosure with no additional …

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-28652Low· 3.1
2w ago

In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check

In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed…

▾ Sunlitgoogle · androidEPSS 0.20%via NVD
CVE-2026-28623Low· 3.3
2w ago

In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check

In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check. This could lead to local information disclosure with no additional execution privileges n…

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-28622Low· 3.3
2w ago

In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permissions bypass

In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User int…

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
GHSA-57v5-wqx3-cgj4Medium· 5.8
2w ago

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAt…

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia OSV
CVE-2026-72790Medium· 5.8
2w ago

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /ap…

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via OSV
CVE-2026-83942High· 7.8
2w ago

Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.

Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-83941Critical· 9.9
2w ago

Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.

Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · entra_idEPSS 0.78%via NVD
CVE-2026-81823Medium· 5.3
2w ago

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.

▾ SunlitAVEVA · Pipeline Integrity MonitorEPSS 0.38%via NVD
CVE-2026-73014High· 7.8
2w ago

Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.

Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.30%via NVD
CVE-2026-72966Medium· 5.5
2w ago

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.30%via NVD
CWE-862 vulnerabilities (CVEs) — page 19 · VulnSea