VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-62207High· 8.8
2mo ago

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient polic…

▾ TwilightEPSS 0.57%via NVD
GHSA-cvpc-hccg-wmw4Medium· 6.3
2mo ago

Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration

Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration

▾ Sunlitverbb · verbb/formievia GHSA
CVE-2026-55548Medium· 4.3
2mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request om…

▾ Sunlitspaceapplications · yamcsEPSS 0.36%via NVD
CVE-2026-44595Medium· 4.3PoC
2mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamc…

▾ Twilightspaceapplications · yamcsEPSS 1.1%via NVD
CVE-2026-15407Medium· 4.3
2mo ago

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it po…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-52870High· 7.6
2mo ago

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

▾ Twilightmcp · mcpEPSS 0.39%via OSV
CVE-2026-59255High· 7.1PoC
2mo ago

BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema

BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens…

▾ MidnightSpecterOps · BloodHoundEPSS 0.44%via NVD
CVE-2026-56742Medium· 5.9
2mo ago

Cilium is a networking, observability, and security solution

Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any S…

▾ Sunlitcilium · ciliumEPSS 0.17%via NVD
CVE-2026-61440Medium· 6.5
2mo ago

PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues

PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-49280Medium
2mo ago

MantisBT: REST API unauthorized Issue status change

MantisBT: REST API unauthorized Issue status change

▾ Sunlitmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-14504Medium· 6.5
2mo ago

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission…

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission…

▾ Sunlitsonatype · nexus_repository_managerEPSS 0.19%via NVD
CVE-2026-58279Medium· 6.5
2mo ago

Azure CycleCloud Elevation of Privilege Vulnerability

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

▾ SunlitMicrosoft · Azure CycleCloud 8.9.1EPSS 0.64%via CVEORG
CVE-2026-55052High· 8.8
2mo ago

Microsoft SharePoint Elevation of Privilege Vulnerability

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.94%via CVEORG
GHSA-7rx3-5wx3-5v76High· 7.7
2mo ago

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

▾ Twilightforgekeep · github.com/forgekeep/nebula-meshvia GHSA
CVE-2026-54052Critical· 9.9
2mo ago

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

▾ Midnightn8n-mcp · n8n-mcpEPSS 0.39%via GHSA
CVE-2025-32781Medium· 6.5
2mo ago

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

▾ Sunlitctrip · com.ctrip.framework.apollo:apolloEPSS 0.41%via GHSA
CVE-2026-10085Medium· 5.4
2mo ago

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct m…

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct m…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-57830NonePoC
2mo ago

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

▾ TwilightEPSS 0.50%via NVD
CVE-2026-15541High· 7.3
2mo ago

A flaw has been found in will-moss Isaiah up to 1.36.9

A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent …

▾ TwilightEPSS 0.54%via NVD
CVE-2026-15507Medium· 6.3
2mo ago

A vulnerability was detected in coollabsio Coolify up to 4.1.1

A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote ex…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-61442High· 7.1
2mo ago

PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role

PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created r…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-9017Medium· 5.3
2mo ago

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to per…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-12994Medium· 5.3
2mo ago

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. This is due to the plugin not properly verifying that a user is authorized to perform an…

▾ SunlitEPSS 0.56%via NVD
CVE-2026-12738Medium· 4.3
2mo ago

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is author…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-12103Medium· 4.3
2mo ago

The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4

The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make…

▾ SunlitEPSS 0.49%via NVD
CVE-2026-7620Medium· 4.3
2mo ago

The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1

The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This m…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-7559Medium· 4.3
2mo ago

The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.3.3

The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.3.3. This is due to the plugin not properly verifying that a user is auth…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-6804Medium· 5.3
2mo ago

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform a…

▾ SunlitEPSS 0.56%via NVD
CVE-2026-6803Medium· 5.3
2mo ago

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions regist…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-3552Medium· 4.3
2mo ago

The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0

The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capabilit…

▾ SunlitEPSS 0.37%via NVD
CWE-862 vulnerabilities (CVEs) — page 35 · VulnSea