VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1331 CVEsRSS

CVE-2026-72798High· 8.6
3w ago

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.43%via GHSA
CVE-2026-72796Medium· 5.8
3w ago

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.35%via GHSA
CVE-2026-72795High· 8.6
3w ago

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.41%via GHSA
CVE-2026-63735High· 8.1
3w ago

SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path

SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path

▾ Twilightsurrealdb · surrealdbEPSS 0.37%via GHSA
CVE-2026-53602Medium
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does n…

▾ Sunlitforgekeep · github.com/forgekeep/nebula-meshEPSS 0.31%via NVD
CVE-2026-53769Medium· 6.5PoC
3w ago

Avo is a framework to create admin panels for Ruby on Rails apps

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload…

▾ Twilightavo-hq · avoEPSS 0.42%via NVD
CVE-2026-85226Medium· 4.3
3w ago

MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other access-control restr…

MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other access-control restr…

▾ Sunlitmisp-project · mispEPSS 0.25%via NVD
CVE-2026-85213High· 7.6
3w ago

Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation

Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read in…

▾ Twilightkillbill · killbillEPSS 0.39%via NVD
CVE-2026-85212High· 8.3
3w ago

CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches

CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoi…

▾ Twilightcrmeb · CRMEBEPSS 0.60%via NVD
CVE-2026-84989High· 7.1
3w ago

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest/v2/edit/tag/tag…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-63219High· 8.6
3w ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolle…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-85433Critical· 9.8
3w ago

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or c…

▾ Midnightthemoos · essential-moosEPSS 0.62%via NVD
CVE-2026-78596Medium· 4.3
3w ago

Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122)

Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Securit…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-78595Medium· 4.3
3w ago

Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122)

Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level …

▾ SunlitEPSS 0.28%via NVD
CVE-2026-84238Critical· 9.8
3w ago

Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

▾ MidnightEPSS 0.48%via NVD
CVE-2026-70178High· 8.5
3w ago

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · fabricEPSS 0.63%via NVD
CVE-2026-85395High· 7.1
3w ago

UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks

UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, min…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-85390High· 7.1
3w ago

Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions

Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create a…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-85309Medium· 5.3
3w ago

Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.

Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.

▾ SunlitEPSS 0.29%via NVD
CVE-2026-84847High· 7.5
3w ago

Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.

Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.

▾ TwilightEPSS 0.35%via NVD
CVE-2026-84758Medium· 6.5
3w ago

Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.

Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.

▾ SunlitEPSS 0.33%via NVD
CVE-2026-55658High· 7.7
3w ago

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the clust…

▾ TwilightEPSS 0.30%via NVD
CVE-2026-85210Medium· 4.3PoC
3w ago

Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles

Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters …

▾ Twilightoppia · oppiaEPSS 0.34%via NVD
CVE-2026-72812Medium· 6.5
3w ago

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.38%via GHSA
CVE-2026-72810High· 8.6
3w ago

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via GHSA
CVE-2026-72808Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.40%via GHSA
CVE-2026-72806Medium· 5.8
3w ago

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents with…

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.43%via OSV
CVE-2026-72804High· 8.6
3w ago

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.43%via GHSA
CVE-2026-72803Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via GHSA
CVE-2026-72800Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeratio…

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via OSV
CWE-862 vulnerabilities (CVEs) — page 23 · VulnSea