CWE-862
CVEs classified under CWE-862, newest first.
1332 CVEsRSS
CVE-2026-66012Critical· 10.0PoCSiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, i…
CVE-2026-58275Critical· 10.0Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
GHSA-h4hf-v6w5-897xHigh· 8.8Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
GHSA-fp43-vj7g-pg92High· 7.5OmniFaces: Forged combined-resource IDs and related output/push boundaries
OmniFaces: Forged combined-resource IDs and related output/push boundaries
CVE-2026-59225Medium· 5.4Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
GHSA-j9fc-w3mr-x6mvHigh· 8.8Budibase: Privilege escalation via public role assignment API missing app-level authorization
Budibase: Privilege escalation via public role assignment API missing app-level authorization
GHSA-4qcj-m5wp-jmf4Medium· 4.3Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
CVE-2026-59226Low· 3.1Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVE-2026-59227Medium· 4.3Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVE-2026-59217Medium· 4.3Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
GHSA-rjg6-39jm-rgg4Critical· 9.9@better-auth/scim: account takeover and stale access via SCIM provider-id collision
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
CVE-2026-55628Medium· 6.1ImageMagick: Policy Bypass in concatenate operation due to missing checks
ImageMagick: Policy Bypass in concatenate operation due to missing checks
GHSA-v3j6-27vc-7pw2Low· 3.3ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
CVE-2026-27422Medium· 5.3Missing Authorization vulnerability in bPlugins YT Player yt-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YT Player: from n/a through 2.1.2.
Missing Authorization vulnerability in bPlugins YT Player yt-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YT Player: from n/a through 2.1.2.
CVE-2026-65895High· 8.5Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can …
CVE-2026-65055Medium· 5.3PoCTaiga taiga-back Private Project Member Roster Disclosure via Unauthenticated filters_data Endpoints
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data…
CVE-2026-47688High· 8.2FOG is a free open-source cloning/imaging/rescue suite/inventory management system
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker v…
CVE-2026-58432Medium· 5.9Gitea: draft release attachment disclosure via missing web authorization
Gitea: draft release attachment disclosure via missing web authorization
CVE-2026-57886Medium· 5.9Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
CVE-2026-58438LowGitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-50105Medium· 4.3Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
CVE-2026-58434LowGitea: Private Repository Metadata Remains Accessible After Access Revocation
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
GHSA-p63j-vcc4-9vmvCritical· 9.4@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
CVE-2026-16216Medium· 4.3A weakness has been identified in geex-arts django-jet up to 1.0.8
A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote.…
CVE-2026-16215Medium· 6.5A security flaw has been discovered in geex-arts django-jet up to 1.0.8
A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possibl…
CVE-2026-16197Medium· 6.3A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation l…
CVE-2026-16123Medium· 6.3A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2
A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation cau…
CVE-2026-16081Medium· 4.3A vulnerability was determined in Sipeed PicoClaw up to 0.2.9
A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched r…
CVE-2026-16106Medium· 4.9A flaw was found in the admin REST API of Keycloak, a solution for identity and access management
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks…
CVE-2026-62218High· 8.8OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger autho…