VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

874 CVEsRSS

CVE-2026-77109High· 8.6
2w ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue d…

▾ Twilightadobe · commerceEPSS 0.69%via NVD
CVE-2026-76202High· 8.2
2w ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue …

▾ Twilightadobe · commerceEPSS 0.67%via NVD
CVE-2026-70283High· 7.0
2w ago

Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.

Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.24%via NVD
CVE-2026-82062Medium· 5.5
2w ago

A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled feature gate in the applyOps command by specifying an internal replication mode value that was not intended to be clie…

A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled feature gate in the applyOps command by specifying an internal replication mode value that was not intended to be clie…

▾ Sunlitmongodb · mongodbEPSS 0.45%via NVD
CVE-2026-82053High· 8.1
2w ago

A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations

A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may exe…

▾ Twilightmongodb · mongodbEPSS 0.41%via NVD
CVE-2026-82074Medium· 6.5
2w ago

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsy…

▾ Sunlitmongodb · mongodbEPSS 0.33%via NVD
CVE-2026-82073Medium· 6.5
2w ago

A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are…

A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data from unauthorized collections when Atlas Search features are…

▾ Sunlitmongodb · mongodbEPSS 0.33%via NVD
CVE-2026-86665High· 7.3PoC
2w ago

A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15

A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is…

▾ Midnightaircheng-org · iWebShop-5EPSS 0.54%via NVD
CVE-2026-73318Low· 3.8PoC
2w ago

XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions

XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can b…

▾ Twilightxenforo · xenforoEPSS 0.49%via NVD
CVE-2026-73317Low· 2.7PoC
2w ago

XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying…

XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized approval queue actions by supplying…

▾ Twilightxenforo · xenforoEPSS 0.41%via NVD
CVE-2026-73313Medium· 6.8PoC
2w ago

XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential d…

XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential d…

▾ Twilightxenforo · xenforoEPSS 0.58%via NVD
CVE-2026-73310Medium· 5.9PoC
2w ago

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one record…

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one record…

▾ Twilightxenforo · xenforoEPSS 0.48%via NVD
CVE-2026-33391Medium· 5.4
2w ago

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access cont…

▾ SunlitNozomi Networks · GuardianEPSS 0.34%via NVD
CVE-2026-33388High· 7.4
2w ago

An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges

An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available ent…

▾ TwilightNozomi Networks · GuardianEPSS 0.40%via NVD
CVE-2026-53638Medium· 4.3
2w ago

Sylius is an Open Source eCommerce Framework on Symfony

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orde…

▾ SunlitSylius · SyliusEPSS 0.28%via NVD
CVE-2026-86274Medium· 5.3PoC
2w ago

A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1

A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoContr…

▾ Twilightprojeto-siga · sigaEPSS 0.74%via NVD
CVE-2026-86544High· 8.1
2w ago

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permis…

▾ Twilightknowns-dev · knownsEPSS 0.58%via NVD
CVE-2026-86498High· 7.7
2w ago

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

▾ TwilightJetBrains · YouTrackEPSS 0.30%via NVD
CVE-2026-86439High· 8.8
2w ago

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory…

▾ Twilightknowns-dev · knownsEPSS 1.1%via NVD
CVE-2026-86437High· 7.2PoC
2w ago

Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live appli…

Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live appli…

▾ Midnightlaradashboard · laradashboardEPSS 0.71%via NVD
CVE-2026-86493Medium· 6.5
2w ago

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

▾ SunlitJetBrains · YouTrackEPSS 0.30%via NVD
CVE-2026-86490Medium· 6.5
2w ago

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

▾ SunlitJetBrains · YouTrackEPSS 0.33%via NVD
CVE-2026-86487Low· 3.1
2w ago

In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

▾ SunlitJetBrains · YouTrackEPSS 0.20%via NVD
CVE-2026-76560High· 7.5
2w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access contr…

▾ TwilightRed Hat · redhat-ds:11EPSS 0.64%via NVD
CVE-2026-84173High· 8.3PoC
2w ago

In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard

In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by su…

▾ MidnightEclipse Foundation · Eclipse AnkaiosEPSS 0.16%via NVD
CVE-2026-86271Medium· 4.7PoC
2w ago

A vulnerability was found in FluentCMS up to 0.0.5

A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS.Services/Permissions/PermissionManager.cs. Performing a manipulation results in missing authorization. It is po…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-86193High· 8.7PoC
3w ago

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch passwor…

▾ Midnightgetgrav · grav-plugin-apiEPSS 0.36%via NVD
CVE-2026-85697Medium· 6.5
3w ago

Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings

Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by l…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-85620High· 8.6
3w ago

Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses

Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clau…

▾ Twilightcrystaldba · postgres-mcpEPSS 0.51%via NVD
CVE-2026-85622Medium· 5.3
3w ago

AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticated users to bind sessions to workspaces they do not belong to

AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticated users to bind sessions to workspaces they do not belong to. At…

▾ SunlitEPSS 0.40%via NVD
CWE-863 vulnerabilities (CVEs) — page 11 · VulnSea