CWE-862
CVEs classified under CWE-862, newest first.
1332 CVEsRSS
CVE-2026-48500Medium· 6.5Filament: Unauthenticated temporary file upload on auth pages
Filament: Unauthenticated temporary file upload on auth pages
CVE-2026-49205Medium· 6.5phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
CVE-2026-55542LowSnipe-IT's S3 signature image retrieval lacks authorization before temporary URL
Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
CVE-2026-56104High· 7.4Chainlit contains a session hijacking vulnerability
Chainlit contains a session hijacking vulnerability
CVE-2026-5139Medium· 5.4Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
CVE-2026-44914High· 7.2Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additio…
CVE-2026-33684Medium· 5.3AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions
AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions
CVE-2026-44585Medium· 5.4Paymenter has broken object level authorization via service reference manipulation on ticket creation
Paymenter has broken object level authorization via service reference manipulation on ticket creation
CVE-2026-50137HighBudibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
CVE-2026-52799High· 7.5Gogs Missing Authorization in Attachment Download
Gogs Missing Authorization in Attachment Download
GHSA-rg7q-4223-phjwHigh· 7.5Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
CVE-2026-48582Critical· 9.6Microsoft Exchange Online Elevation of Privilege Vulnerability
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-55414Medium· 5.3NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
GHSA-c8qj-jx8j-fg2wCriticalDotVVM: Missing authorization in AuthorizeActionFilter
DotVVM: Missing authorization in AuthorizeActionFilter
GHSA-mqq5-j7w8-2hghHigh· 7.5AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
GHSA-mxjx-28vx-xjjjMedium· 5.9Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
GHSA-vmf9-xx9w-86wxHigh· 8.3PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
GHSA-5qw8-f2g9-ff29High· 8.2PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
GHSA-qvpf-j64c-jmhrHigh· 8.3PraisonAI Slack app_mention bypasses configured user/channel authorization
PraisonAI Slack app_mention bypasses configured user/channel authorization
CVE-2026-11719HighMCP Toolbox for Databases: authenticated authorization bypass
MCP Toolbox for Databases: authenticated authorization bypass
GHSA-fq2m-6wqh-x44gCritical· 9.8PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
GHSA-x8cv-xmq7-p8xpCritical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
GHSA-892r-p3jq-jp24Critical· 9.8PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
GHSA-j4f3-55x4-r6q2Critical· 9.8npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
GHSA-h2w2-v7j6-xqm4High· 8.8npm PraisonAI AgentLoop onToolCall approval runs after tool execution
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
CVE-2026-49274MediumKirby: `pages.access` permission is not checked in the pages picker for parent pages
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
CVE-2026-54004MediumKirby: Access to files of top-level drafts is not protected by permissions
Kirby: Access to files of top-level drafts is not protected by permissions
CVE-2026-54005HighKirby: `pages.access` permission is not checked in the `site/find` REST API route
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
CVE-2026-54695High· 7.5Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
GHSA-hjwc-26pj-v3pmHighAgenticMail: Cross-agent task authorization bypass in AgenticMail API
AgenticMail: Cross-agent task authorization bypass in AgenticMail API