VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-76032Medium· 4.3
1mo ago

Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user

Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the resul…

▾ Sunlitpydio · cellsEPSS 0.38%via NVD
CVE-2026-69189High· 7.6
1mo ago

Hoppscotch is an open source API development ecosystem

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose an…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-67440None
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js return device-discover…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-53453None
1mo ago

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did n…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-55106Medium· 5.3
1mo ago

authentik is an open-source identity provider

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach th…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-75853High· 8.8
1mo ago

ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never…

ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never…

▾ TwilightEPSS 0.59%via NVD
CVE-2026-75850Medium· 4.2
1mo ago

ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers

ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers. Because no principal is bound on the worker thread, the engine's fine-grained per-type ACL layer (LocalBucket.c…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-75846High· 7.1
1mo ago

ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement

ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a server-side function w…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-75837Critical· 9.1
1mo ago

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-ad…

▾ Midnightgetgrav · getgrav/gravEPSS 0.49%via NVD
CVE-2026-75836High· 8.8
1mo ago

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction()

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items listing endpoint correct…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-75835Medium· 4.3
1mo ago

Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php)

Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request's API key scopes, relying inst…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-45124Medium· 4.3
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-75832Medium· 4.3
1mo ago

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope()

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/<name> s…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-75858High· 7.8
1mo ago

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine trea…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.36%via NVD
CVE-2026-67443None
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decod…

▾ SunlitEPSS 0.69%via NVD
CVE-2026-65959Medium· 5.3
1mo ago

Vitess is a database clustering system for horizontal scaling of MySQL

Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() wi…

▾ Sunlitvitess · vitess.io/vitessEPSS 0.43%via NVD
CVE-2026-71307High· 7.7
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned raw optio…

▾ Twilightlemur · lemurEPSS 0.31%via NVD
CVE-2026-71308High· 8.1
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a Certific…

▾ Twilightlemur · lemurEPSS 0.32%via NVD
CVE-2026-71317Medium· 6.5
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORITY_CREATION was false. AssociatedAuthoritySchema resolved …

▾ Sunlitlemur · lemurEPSS 0.10%via NVD
CVE-2026-71322Medium· 4.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/certificates//export. A plugin declaring requires_key false …

▾ Sunlitlemur · lemurEPSS 0.23%via NVD
CVE-2026-47721Medium· 6.3
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for schedule…

▾ Sunlitfuxa-server · fuxa-serverEPSS 0.43%via NVD
CVE-2026-74869High· 7.7
1mo ago

stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership

stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership. Attackers…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-75109High· 7.1PoC
1mo ago

Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers

Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own.

▾ Midnightdetermined-ai · determinedEPSS 0.29%via NVD
CVE-2026-59829Medium· 4.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and permalink) of the private message attac…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-55704Medium· 4.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, could still receive shared-draft entries…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-53960Medium· 5.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data,…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-75108Medium· 5.4PoC
1mo ago

Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not granted access to

Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not granted access to. Attackers can call these endpoints with …

▾ Twilightnext-terminal · next-terminalEPSS 0.29%via NVD
CVE-2026-75049Medium· 6.5
1mo ago

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

▾ Sunlitjetbrains · youtrackEPSS 0.34%via NVD
CVE-2026-75046Medium· 4.3
1mo ago

In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

▾ Sunlitjetbrains · youtrackEPSS 0.27%via NVD
CVE-2026-75044High· 8.1
1mo ago

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

▾ Twilightjetbrains · youtrackEPSS 0.38%via NVD
CWE-862 vulnerabilities (CVEs) — page 28 · VulnSea