CWE-862
CVEs classified under CWE-862, newest first.
1327 CVEsRSS
CVE-2026-96680Medium· 4.3PoCA vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2
A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of the component External Me…
CVE-2026-96603High· 7.3PoCA vulnerability has been found in Abdurrab5 online-makeup-store
A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of the argument adminid leads to missing…
CVE-2026-67218Low· 2.1⚖ disputedRabbitMQ is a messaging and streaming broker
RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0, accept_content/2 at line 56 calls rabbit_stream_manager:create_super_stream/... directly after is_authorized (which only checks the managem…
CVE-2026-66075Low· 2.3⚖ disputedRabbitMQ is a messaging and streaming broker
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, is_authorized/2 for the /federation-links/.../restart route uses is_authorized_monitor (accepts the monitoring tag), while allowed…
CVE-2026-66069Low· 2.3⚖ disputedRabbitMQ is a messaging and streaming broker
RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_authorized_monitor for all methods. DELETE resets rabbit_core_metrics:reset_auth_attempt_metrics(). Impact is cosmetic (cou…
CVE-2026-96551Medium· 4.3PoCA vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8
A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java. Executing a manipulation c…
CVE-2026-84719Critical· 9.9A flaw was found in the Ansible Automation Platform automation-controller
A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node a…
CVE-2026-66076Low· 2.3PoC⚖ disputedRabbitMQ is a messaging and streaming broker
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. Th…
CVE-2026-76648High· 8.5CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC
CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'r…
CVE-2026-76089High· 7.7Formie is a Craft CMS plugin for creating forms
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-s…
CVE-2026-76087High· 8.2Formie is a Craft CMS plugin for creating forms
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submit action in SubmissionsController::actionSubmit trusts a client-supplied submissionId when loading an incomplete subm…
CVE-2026-76086High· 8.5Formie is a Craft CMS plugin for creating forms
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration…
CVE-2026-71460Medium· 4.3/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user
/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuse…
CVE-2026-52744Medium· 5.3GoCD is a continuous deliver server
GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authent…
CVE-2026-71459Medium· 5.0JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user
JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user. The view uses raw get_object_or_…
CVE-2026-93529Medium· 6.5Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
CVE-2026-93620Medium· 6.5Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
CVE-2026-94080Medium· 5.3Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
CVE-2026-94079Medium· 5.3Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
CVE-2026-94498Medium· 6.5Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
CVE-2026-94679Medium· 5.4Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
CVE-2026-95513High· 7.5Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
CVE-2026-95527Medium· 6.5Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
CVE-2026-95604High· 7.5Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
CVE-2026-86867Medium· 6.5Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls
Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pag…
CVE-2026-95846High· 7.5PoCMoquette is a lightweight Java MQTT broker
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can conf…
CVE-2026-18179Medium· 6.5IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.
CVE-2026-18177High· 7.1IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
CVE-2026-96446Medium· 4.2A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak
A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is alre…
CVE-2026-87848Low· 3.7The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthen…
The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthen…