VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

753 CVEsRSS

CVE-2026-77560High· 8.1
today

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege u…

Twilighttinyauthapp · tinyauthvia NVD
CVE-2026-63342Medium· 6.3
today

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-ta…

Sunlithatchet-dev · hatchetvia NVD
CVE-2026-55563High· 8.9
today

Feast is the open source feature store for AI and machine learning

Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_tests.yml uses pull_request_target with the synchronize event and preserves ok-to-test, approved, or lgtm labels across…

Twilightfeast-dev · feastvia NVD
CVE-2026-88978Medium· 4.3
today

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and …

Sunlithatchet-dev · hatchetvia NVD
CVE-2026-71543None
today

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated…

Sunlitvia NVD
CVE-2026-55625Medium· 4.9
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and…

Sunlitvia NVD
CVE-2026-55060Low· 3.7
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source c…

Sunlitgocd · gocdvia NVD
CVE-2026-52742Medium· 5.1
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for gro…

Sunlitgocd · gocdvia NVD
CVE-2026-52740Medium· 5.3
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with no…

Sunlitgocd · gocdvia NVD
CVE-2026-80110High· 8.1
today

A flaw was found in pki-core

A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to ove…

TwilightRed Hat · pki-corevia NVD
CVE-2026-52743Medium· 4.3
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can gu…

Sunlitgocd · gocdvia NVD
CVE-2026-93954Medium· 4.3
2d ago

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of …

Sunlitgrimmory-tools · grimmoryEPSS 0.38%via NVD
CVE-2026-1242Medium· 4.3
2d ago

The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator…

The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator…

Sunlitblockspare · BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business WebsitesEPSS 0.18%via NVD
CVE-2026-92403Low· 3.7
2d ago

The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different regis…

The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different regis…

SunlitEPSS 0.16%via NVD
CVE-2026-11540Medium· 5.3
3d ago

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

SunlitIBM · WebSphere Application ServerEPSS 0.30%via NVD
GHSA-xwmw-prc4-v3crHigh· 8.8
3d ago

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

Twilightobot-platform · github.com/obot-platform/obotvia OSV
GHSA-pr6h-vr44-xq8jMedium· 5.3
3d ago

Obot: MCP Registry API readable without authentication

Obot: MCP Registry API readable without authentication

Sunlitobot-platform · github.com/obot-platform/obotvia OSV
CVE-2026-81178Low· 3.5
3d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share consumer joins the same c…

SunlitSyslifters · sysreptorEPSS 0.21%via NVD
CVE-2026-61672High· 7.1
3d ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assume…

Twilightprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.20%via NVD
CVE-2026-93594High· 8.1PoC
3d ago

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or th…

MidnightArcadeData · arcadedbEPSS 0.34%via NVD
CVE-2026-93593High· 8.1
3d ago

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privil…

TwilightArcadeData · arcadedbEPSS 0.22%via NVD
CVE-2026-75157NonePoC
3d ago

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently sup…

TwilightApache Software Foundation · apache-airflowEPSS 0.17%via NVD
CVE-2026-68791High· 8.6
4d ago

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Azure Machine LearningEPSS 0.55%via NVD
CVE-2026-93379Medium· 4.3
4d ago

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-92992Medium· 6.3PoC
4d ago

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authoriza…

TwilightDromara · mayfly-goEPSS 0.28%via NVD
CVE-2026-92904Medium· 4.3
4d ago

A flaw was found in the foreman_remote_execution plugin's template invocations controller

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filt…

SunlitRed Hat · rubygem-foreman_remote_executionEPSS 0.25%via NVD
CVE-2026-92611Medium· 4.8
4d ago

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

SunlitEclipse Foundation · Eclipse AnkaiosEPSS 0.21%via NVD
CVE-2026-92893Medium· 4.3
4d ago

A flaw was found in the foreman_ansible plugin's Ansible inventory API

A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An…

SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.28%via NVD
CVE-2026-81439Low· 3.7
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechani…

SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.19%via NVD
CVE-2026-78426Low· 3.7
4d ago

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equ…

Sunlitgo · neuvectorEPSS 0.12%via NVD
CWE-863 vulnerabilities (CVEs) · VulnSea