VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-66012Critical· 10.0PoC
2mo ago

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, i…

▾ Abyssalsiyuan-note · siyuanEPSS 0.76%via NVD
CVE-2026-58275Critical· 10.0
2mo ago

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_dnsEPSS 0.92%via NVD
GHSA-h4hf-v6w5-897xHigh· 8.8
2mo ago

Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account

Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account

▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-fp43-vj7g-pg92High· 7.5
2mo ago

OmniFaces: Forged combined-resource IDs and related output/push boundaries

OmniFaces: Forged combined-resource IDs and related output/push boundaries

▾ Twilightomnifaces · org.omnifaces:omnifacesvia GHSA
CVE-2026-59225Medium· 5.4
2mo ago

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
GHSA-j9fc-w3mr-x6mvHigh· 8.8
2mo ago

Budibase: Privilege escalation via public role assignment API missing app-level authorization

Budibase: Privilege escalation via public role assignment API missing app-level authorization

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-4qcj-m5wp-jmf4Medium· 4.3
2mo ago

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

▾ Sunlitbudibase · @budibase/servervia GHSA
CVE-2026-59226Low· 3.1
2mo ago

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

▾ Sunlitopen-webui · open-webuiEPSS 0.53%via GHSA
CVE-2026-59227Medium· 4.3
2mo ago

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

▾ Sunlitopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-59217Medium· 4.3
2mo ago

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
GHSA-rjg6-39jm-rgg4Critical· 9.9
2mo ago

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

▾ Midnightbetter-auth · @better-auth/scimvia GHSA
CVE-2026-55628Medium· 6.1
2mo ago

ImageMagick: Policy Bypass in concatenate operation due to missing checks

ImageMagick: Policy Bypass in concatenate operation due to missing checks

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.14%via GHSA
GHSA-v3j6-27vc-7pw2Low· 3.3
2mo ago

ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check

ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-27422Medium· 5.3
2mo ago

Missing Authorization vulnerability in bPlugins YT Player yt-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YT Player: from n/a through 2.1.2.

Missing Authorization vulnerability in bPlugins YT Player yt-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YT Player: from n/a through 2.1.2.

▾ SunlitbPlugins · yt-playerEPSS 0.29%via NVD
CVE-2026-65895High· 8.5
2mo ago

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can …

▾ TwilightEPSS 0.33%via NVD
CVE-2026-65055Medium· 5.3PoC
2mo ago

Taiga taiga-back Private Project Member Roster Disclosure via Unauthenticated filters_data Endpoints

Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data…

▾ TwilightTaiga · taiga-backEPSS 0.43%via CVEORG
CVE-2026-47688High· 8.2
2mo ago

FOG is a free open-source cloning/imaging/rescue suite/inventory management system

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker v…

▾ Twilightfogproject · fogprojectEPSS 0.27%via NVD
CVE-2026-58432Medium· 5.9
2mo ago

Gitea: draft release attachment disclosure via missing web authorization

Gitea: draft release attachment disclosure via missing web authorization

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-57886Medium· 5.9
2mo ago

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.31%via GHSA
CVE-2026-58438Low
2mo ago

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-50105Medium· 4.3
2mo ago

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-58434Low
2mo ago

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.47%via GHSA
GHSA-p63j-vcc4-9vmvCritical· 9.4
2mo ago

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

▾ Midnightvitest · @vitest/browservia GHSA
CVE-2026-16216Medium· 4.3
2mo ago

A weakness has been identified in geex-arts django-jet up to 1.0.8

A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote.…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-16215Medium· 6.5
2mo ago

A security flaw has been discovered in geex-arts django-jet up to 1.0.8

A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possibl…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-16197Medium· 6.3
2mo ago

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation l…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-16123Medium· 6.3
2mo ago

A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2

A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation cau…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-16081Medium· 4.3
2mo ago

A vulnerability was determined in Sipeed PicoClaw up to 0.2.9

A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched r…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-16106Medium· 4.9
2mo ago

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks…

▾ Sunlitredhat · build_of_keycloakEPSS 0.42%via NVD
CVE-2026-62218High· 8.8
2mo ago

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger autho…

▾ TwilightEPSS 0.45%via NVD
CWE-862 vulnerabilities (CVEs) — page 34 · VulnSea