VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1327 CVEsRSS

CVE-2026-63431Medium· 6.5
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_single_deduction before loading records sel…

▾ Sunlithorilla · horilla-hrvia NVD
CVE-2026-100417Low· 3.1
2d ago

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileCon…

▾ Sunlitrustdesk · rustdeskvia NVD
CVE-2026-100388Medium· 5.4
2d ago

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions …

▾ Sunlitrustdesk · rustdeskvia NVD
CVE-2026-100378Medium· 5.3
2d ago

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: from * before 1.46.1, 1.45.…

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: from * before 1.46.1, 1.45.…

▾ SunlitWikimedia Foundation · Mediawiki - Translate ExtensionEPSS 0.27%via NVD
CVE-2026-63205Medium· 5.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img t…

▾ Sunlitzammad · zammadvia NVD
CVE-2026-53626High· 7.1
2d ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can …

▾ Twilightglpi-project · glpivia NVD
CVE-2026-63204Low· 2.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identifier to the ticket summarize endpoint and receive the AI prov…

▾ Sunlitzammad · zammadvia NVD
CVE-2026-100303Medium· 5.4
2d ago

TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories

TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms o…

▾ SunlitTDuckCloud · tduck-survey-formvia NVD
CVE-2026-53627Medium· 6.0
2d ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform through the …

▾ Sunlitglpi-project · glpivia NVD
CVE-2026-53625High· 7.5PoC
2d ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the le…

▾ Midnightglpi-project · glpivia NVD
CVE-2026-100305Medium· 4.3PoC
2d ago

TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create

TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a form's key can submit unlimited entries to any form, bypass…

▾ TwilightTDuckCloud · tduck-survey-formvia NVD
CVE-2026-56726Medium· 5.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation boundaries between agents. Any authenticated agent, even one with no active tickets assigned to them, c…

▾ Sunlitzammad · zammadvia NVD
CVE-2026-56730Low· 2.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to acces…

▾ Sunlitzammad · zammadvia NVD
CVE-2026-65828Low· 2.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-supplied form_id without verifying that …

▾ Sunlitzammad · zammadvia NVD
CVE-2026-66078Low· 2.1
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, protected tag bypass via bulk-delete. dELETE /api/users/:name refuses to delete users tagged protected (rabbitmgmtwmuser:deleteresou…

▾ Sunlitrabbitmq · rabbitmq-servervia NVD
CVE-2026-67241Medium· 4.8
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, AMQP 1.0 management exchange.declare skips alternate-exchange permission check. pUT /exchanges/:name (lines 192-240) checks only configure on the declared ex…

▾ Sunlitrabbitmq · rabbitmq-servervia NVD
CVE-2026-61837Medium· 6.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 management GET /bindings exposes full binding topology to any authenticated AMQP user without resource/management permission checks…

▾ Sunlitrabbitmq · rabbitmq-servervia NVD
CVE-2026-67407Medium· 5.1
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3 and 4.2.9 and 4.1.14 and 4.0.23, Incomplete fix for CVE-2026-44838: escaperegexchar/1 does not escape -, leaving room for an MQTT topic permission bypass. the CVE-2026-…

▾ Sunlitrabbitmq · rabbitmq-servervia NVD
CVE-2026-95835Medium· 5.6
2d ago

Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_rem…

Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_rem…

▾ SunlitKovid Goyal · kittyvia NVD
CVE-2026-67421Medium· 4.5PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAu…

▾ Twilightrabbitmq · rabbitmq-servervia NVD
CVE-2026-67420Low· 2.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAuth credential refresh retains revoked runtime tags. when an existing AMQP connection refreshes from an OAuth token th…

▾ Sunlitrabbitmq · rabbitmq-servervia NVD
CVE-2026-67412Medium· 6.0PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policy…

▾ Twilightrabbitmq · rabbitmq-servervia NVD
CVE-2026-56724High· 7.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area has been identified. Under certain conditions, data validation for linked i…

▾ Twilightzammad · zammadvia NVD
CVE-2026-93363Medium· 4.3
2d ago

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attac…

▾ Sunlitpayloadcms · payloadvia NVD
CVE-2026-93364Medium· 4.3
2d ago

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save req…

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save req…

▾ SunlitBludit · Bludit CMSvia NVD
CVE-2026-80432Medium· 6.0
2d ago

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never co…

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never co…

▾ SunlitKovid Goyal · kittyvia NVD
CVE-2026-93365Medium· 6.5
2d ago

Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of private drafts and scheduled posts belonging to any other user, includ…

Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of private drafts and scheduled posts belonging to any other user, includ…

▾ SunlitBludit · Bludit CMSvia NVD
CVE-2026-97898High· 8.4
2d ago

Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service

Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the…

▾ Twilightakia · akiavia NVD
CVE-2026-92713High· 8.1
2d ago

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This m…

▾ Twilightwpchill · Modula Image Gallery – Photo Grid & Video GalleryEPSS 0.27%via NVD
CVE-2026-89406High· 7.5
2d ago

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function…

▾ Twilightwpchill · Modula Image Gallery – Photo Grid & Video GalleryEPSS 0.39%via NVD
CWE-862 vulnerabilities (CVEs) — page 2 · VulnSea