CWE-862
CVEs classified under CWE-862, newest first.
1332 CVEsRSS
GHSA-vjc7-jrh9-9j86Critical· 10.09router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
GHSA-x76w-8c62-48mgMediumCraft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
CVE-2026-49445Critical· 9.2Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
CVE-2026-27771High· 8.2PoCGitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
CVE-2026-25038NoneGitea 1.26.2 allows unauthorized users to access labels of private organizations.
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
CVE-2026-14460High· 8.8Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5.
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5.
CVE-2026-11398Medium· 5.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is a…
CVE-2026-9230Medium· 4.3The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is author…
CVE-2026-12557Medium· 5.3The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…
CVE-2026-59800Critical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection
GHSA-j5mc-p8qg-39j7LowKimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
CVE-2026-50282HighCraft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
GHSA-g6g7-pvmx-m74pCritical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection
CVE-2026-50284HighCraft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
GHSA-f9ff-5x35-7gfwHighGrackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
GHSA-qjpc-qf9m-xwmrHigh· 8.8OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
GHSA-hcm3-8f6r-6xwgMedium· 6.5OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
GHSA-3wqp-prf6-2m72Low· 3.1OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
CVE-2026-53818Medium· 6.6OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
CVE-2026-53815High· 6.5OpenClaw: Message read actions could skip channel allowlist checks
OpenClaw: Message read actions could skip channel allowlist checks
GHSA-mgq6-vr84-7m2jHigh· 8.0OpenClaw: QQBot native approval buttons did not enforce configured approver identity
OpenClaw: QQBot native approval buttons did not enforce configured approver identity
GHSA-hw9r-h9mr-4jffHigh· 8.8OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
GHSA-wp87-mgvq-5j93Medium· 6.5SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
GHSA-gcwr-5mrf-fvchMedium· 5.4SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
CVE-2026-46487High· 7.5GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
CVE-2026-58373Medium· 4.3CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing…
CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing…
CVE-2026-49821High· 7.7Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
CVE-2026-49822High· 7.7Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
CVE-2026-48592Mediumoban_web missing authorization check on `save-job` event handler
oban_web missing authorization check on `save-job` event handler