CWE-862
CVEs classified under CWE-862, newest first.
1332 CVEsRSS
CVE-2026-53844Medium· 6.5OpenClaw: memory-wiki shared search could miss session visibility checks
OpenClaw: memory-wiki shared search could miss session visibility checks
CVE-2026-53850MediumOpenClaw: Focus command could miss controlScope enforcement
OpenClaw: Focus command could miss controlScope enforcement
CVE-2026-54415High· 8.1PoCMissing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…
CVE-2026-54010High· 8.3Open WebUI: Forged chat-file link allows cross-user file read and deletion
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVE-2026-54012High· 7.1Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVE-2026-54016Medium· 4.3Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
CVE-2026-54019Medium· 6.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
CVE-2026-12515Medium· 4.3katello: missing repository authorization in content_uploads exposes cross-product content existence
katello: missing repository authorization in content_uploads exposes cross-product content existence
CVE-2026-55518Critical· 9.6Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
CVE-2026-0158Medium· 4.0In Camera, there is a possible unauthorized way to access photos due to a missing permission check
In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi…
CVE-2026-0145Medium· 4.0In keymint, there is a possible Permission Bypass due to a logic error in the code
In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-54322High· 7.7Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
GHSA-6jm4-83g2-35gvMedium· 6.5Duplicate Advisory: memory-wiki shared search could miss session visibility checks
Duplicate Advisory: memory-wiki shared search could miss session visibility checks
GHSA-gw2c-6hcg-5g52Medium· 5.5Duplicate Advisory: Focus command could miss controlScope enforcement
Duplicate Advisory: Focus command could miss controlScope enforcement
GHSA-c8w7-9w9h-x69qMedium· 5.3Duplicate Advisory: Slack reaction events could ignore reaction notification settings
Duplicate Advisory: Slack reaction events could ignore reaction notification settings
GHSA-v383-2wgg-v483High· 8.1Duplicate Advisory: Shell inline-command parsing could miss an allowlist check
Duplicate Advisory: Shell inline-command parsing could miss an allowlist check
CVE-2026-25714Medium· 4.3Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw
Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw
CVE-2026-27783Medium· 4.3Gitea: Missing repository-unit authorization on issue-template API endpoints
Gitea: Missing repository-unit authorization on issue-template API endpoints
GHSA-wqvq-jvpq-h66fMedium· 5.4Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
CVE-2026-53633Critical· 9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
CVE-2026-48151High· 7.5Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
CVE-2026-47351MediumTYPO3 CMS: Broken Access Control in Media Module
TYPO3 CMS: Broken Access Control in Media Module
CVE-2026-47352MediumTYPO3 CMS has Broken Access Control in Backend API
TYPO3 CMS has Broken Access Control in Backend API
CVE-2026-47346HighTYPO3 CMS has Broken Access Control in its Form Framework
TYPO3 CMS has Broken Access Control in its Form Framework
CVE-2026-47350MediumTYPO3 CMS has Broken Access Control in its DataHandler
TYPO3 CMS has Broken Access Control in its DataHandler
CVE-2026-49741HighTYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
CVE-2026-47343HighTYPO3 CMS: Destructive Actions on File Mount Folders
TYPO3 CMS: Destructive Actions on File Mount Folders
CVE-2026-47349MediumTYPO3 CMS has Broken Access Control in the Recycler Module
TYPO3 CMS has Broken Access Control in the Recycler Module
CVE-2026-11607HighTYPO3 CMS has Broken Access Control in its Form Framework
TYPO3 CMS has Broken Access Control in its Form Framework
CVE-2023-32959Medium· 4.3Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.
Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.