VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2023-25969Medium· 5.4
3mo ago

Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Contact Form & Lead Form Elementor Builder: from n/a…

Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Contact Form & Lead Form Elementor Builder: from n/a…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-0272High· 7.2
3mo ago

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk…

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk…

▾ Twilightpaloaltonetworks · pan-osEPSS 0.26%via NVD
CVE-2026-47281Critical· 9.6
3mo ago

Visual Studio Code Elevation of Privilege Vulnerability

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Visual Studio CodeEPSS 0.76%via CVEORG
CVE-2026-39910High· 8.8
3mo ago

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines …

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines …

▾ TwilightEPSS 0.47%via NVD
CVE-2026-47724Critical· 9.9
3mo ago

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

▾ Midnightjuev · github.com/juev/nebula-meshEPSS 0.48%via GHSA
CVE-2026-4881Medium· 6.5
3mo ago

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.

▾ Sunlitoctopus · octopus_serverEPSS 0.37%via NVD
CVE-2026-42318None
3mo ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to recei…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-45285Medium· 6.4
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added vi…

▾ Sunlitnextcloud · nextcloud_serverEPSS 0.49%via NVD
CVE-2026-32905High· 8.3
4mo ago

OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers wi…

▾ TwilightOpenClaw · OpenClawEPSS 0.40%via CVEORG
CVE-2026-47740High· 8.1
4mo ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate or…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-47125High· 8.8
4mo ago

Arcane is an interface for managing Docker containers, images, networks, and volumes

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitut…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-45632Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belongi…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-35630High· 8.0
4mo ago

OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin…

▾ TwilightOpenClaw · OpenClawEPSS 0.36%via CVEORG
CVE-2026-3294High· 8.8
4mo ago

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Suc…

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Suc…

▾ Twilighttp-link · re305_firmwareEPSS 0.57%via NVD
CVE-2026-39833Medium· 5.5⚖ disputed
4mo ago

golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation (CVE-2026-39833)

A flaw was found in golang.org/x/crypto/ssh/agent. The NewKeyring() function, which creates an in-memory keyring, failed to enforce the ConfirmBeforeUse constraint on keys. This allowed keys configured to require user confirmation before u…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
CVE-2026-39831High· 8.1
4mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check (CVE-2026-39831)

A flaw was found in golang.org/x/crypto/ssh. The Verify() method, responsible for FIDO/U2F security key types, did not properly check for user presence. This allowed signatures to be accepted without requiring a physical touch on the hardw…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.49%via CSAF
CVE-2026-8237Medium· 5.3PoC
4mo ago

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message

Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, incl…

▾ Twilightconcretecms · concrete_cmsEPSS 0.74%via NVD
CVE-2026-33137NonePoC
4mo ago

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17…

▾ TwilightEPSS 0.88%via NVD
CVE-2026-21836Medium· 6.5
4mo ago

The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability

The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query.  This could enable…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-45443Medium· 5.0
4mo ago

Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for Elementor Forms + Drag And D…

Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for Elementor Forms + Drag And D…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-26083Critical· 9.8
4mo ago

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, Forti…

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, Forti…

▾ Midnightfortinet · fortisandboxEPSS 0.50%via NVD
CVE-2026-20696Medium· 5.5
4mo ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.4. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.12%via NVD
CVE-2026-20193Medium· 4.3
4mo ago

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an&nbsp;authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. Thi…

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an&nbsp;authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. Thi…

▾ Sunlitcisco · identity_services_engineEPSS 0.22%via NVD
CVE-2026-20189Medium· 4.3
4mo ago

A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an&nbsp;authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authori…

A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an&nbsp;authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authori…

▾ Sunlitcisco · prime_infrastructureEPSS 0.21%via NVD
CVE-2026-5488Medium· 5.3
5mo ago

The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2

The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and res…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-6235Critical· 9.8
5mo ago

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user …

▾ MidnightEPSS 0.67%via NVD
CVE-2025-15565Medium· 5.3
5mo ago

The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0

The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated at…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-34184Critical· 9.1
5mo ago

AlanWeb SCADA does not enforce authorization for some directories

AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the c…

▾ Midnighthydrosystem.poznan · control_systemEPSS 0.46%via NVD
CVE-2025-9484Medium· 4.3
5mo ago

GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other us…

GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other us…

▾ Sunlitgitlab · gitlabEPSS 0.26%via NVD
CVE-2026-0814Medium· 4.3
5mo ago

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possi…

▾ SunlitEPSS 0.30%via NVD
CWE-862 vulnerabilities (CVEs) — page 41 · VulnSea