VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-82633Medium· 4.3
4w ago

Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users

Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{i…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-82475High· 8.1
4w ago

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants'…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-81346Medium· 4.3
4w ago

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.

▾ SunlitEPSS 0.25%via NVD
CVE-2026-19430Medium· 5.3
4w ago

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and downlo…

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and downlo…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-18234Medium· 6.5
4w ago

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated u…

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated u…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-18233Medium· 6.5
4w ago

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as complet…

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as complet…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-82279High· 8.1PoC
1mo ago

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename …

▾ Midnighthyperdxio · hyperdxEPSS 0.33%via NVD
CVE-2026-82273Medium· 6.5PoC
1mo ago

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GE…

▾ Twilightmastra-ai · @mastra/serverEPSS 0.38%via NVD
CVE-2026-82267Medium· 5.4
1mo ago

Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers

Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers. Authenticated users can guess resource names to obtain internal id…

▾ Sunlitmoghtech · komodoEPSS 0.30%via NVD
CVE-2026-68929NonePoC
1mo ago

FastGPT is an open-source LLM platform for building AI applications on a knowledge base

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated iden…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-75339High· 8.8
1mo ago

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.

▾ TwilightEPSS 0.42%via NVD
CVE-2026-75813High· 7.5
1mo ago

Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings

Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.

▾ TwilightEPSS 0.36%via NVD
CVE-2026-56100High· 8.1PoC
1mo ago

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected int…

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected int…

▾ MidnightSpringBlade · SpringBladeEPSS 0.53%via NVD
CVE-2026-55638High· 8.6
1mo ago

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

▾ Twilight9router · 9routerEPSS 0.61%via GHSA
CVE-2026-55476Medium
1mo ago

Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter

Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.34%via GHSA
CVE-2026-55064Medium· 4.3
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to…

▾ Sunlitapi · code.vikunja.io/apiEPSS 0.37%via NVD
CVE-2026-55521High· 8.8
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and T…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.52%via NVD
CVE-2026-55545Medium· 6.5
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.45%via NVD
CVE-2026-55547Medium· 4.3
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.jav…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.34%via NVD
CVE-2026-54746Medium· 6.4
1mo ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the…

▾ Sunlithatchet-dev · github.com/hatchet-dev/hatchetEPSS 0.37%via NVD
CVE-2026-81335High· 7.5
1mo ago

Baserow dispatches an Application Builder data source without acting on the result of its permission check

Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared with a permissio…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-81035High· 8.1
1mo ago

Midday allows any member of a team to delete it

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of t…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-81027High· 8.5
1mo ago

one-api gates one of its two channel-pinning paths and not the other

one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-80191High· 7.5
1mo ago

GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user

GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition re…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-80348High· 8.8
1mo ago

TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app/controller/patch/PatchController.js make no such call

TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app/controller/patch/PatchController.js make no such call. uploadAndPublish accepts a package upload and then build…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-77507Medium· 5.3
1mo ago

Weblate is a web-based continuous localization platform used to manage software translations

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users t…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-80346High· 7.1
1mo ago

StarRocks performs no privilege check when a legacy synchronous materialized view is dropped

StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, but visitDropMaterializedViewStatement …

▾ TwilightEPSS 0.53%via NVD
CVE-2026-80193High· 8.8
1mo ago

Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets

Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet re…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-54569Critical· 9.8
1mo ago

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite.core Vulnerable to Eval Injection and Missing Authorization

▾ Midnightsenaite-core · senaite-coreEPSS 1.2%via OSV
CVE-2026-54523Critical· 9.6
1mo ago

Kyverno is a policy engine designed for cloud native platform engineering teams

Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to …

▾ Midnightkyverno · github.com/kyverno/kyvernoEPSS 0.47%via NVD
CWE-862 vulnerabilities (CVEs) — page 25 · VulnSea