VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

874 CVEsRSS

CVE-2026-85619High· 7.5
3w ago

AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces

AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID wi…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-85592Low· 3.7
3w ago

phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all callers when main.enableAskQuestions is enabled, ignoring the records…

phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all callers when main.enableAskQuestions is enabled, ignoring the records…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-85587None
3w ago

phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content

phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoint…

▾ SunlitEPSS 0.36%via NVD
CVE-2025-15691Medium· 5.3
3w ago

The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthentic…

The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthentic…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-16941Medium· 4.3
3w ago

IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.

IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.

▾ Sunlitibm · iEPSS 0.22%via NVD
CVE-2026-19283High· 7.7
3w ago

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying…

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying…

▾ TwilightIBM · Observability with Instana (Agent)EPSS 0.31%via NVD
CVE-2026-85538None
3w ago

An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute deletion paths relied on organ…

An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute deletion paths relied on organ…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-4644None
3w ago

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project…

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-85597Critical· 9.1
3w ago

Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host…

Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host…

▾ Midnighttraefik · traefikEPSS 0.35%via NVD
CVE-2026-63733Medium· 4.3
3w ago

SurrealDB: Writes in a PERMISSIONS clause bypass table permissions

SurrealDB: Writes in a PERMISSIONS clause bypass table permissions

▾ Sunlitsurrealdb-core · surrealdb-coreEPSS 0.29%via GHSA
CVE-2026-72792Medium· 5.8
3w ago

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via GHSA
CVE-2026-53769Medium· 6.5PoC
3w ago

Avo is a framework to create admin panels for Ruby on Rails apps

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload…

▾ Twilightavo-hq · avoEPSS 0.42%via NVD
CVE-2026-85093Medium· 6.5PoC
3w ago

Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points

Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conver…

▾ Twilightcheshire-cat-ai · coreEPSS 0.41%via NVD
CVE-2026-85166Medium· 6.5
3w ago

n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node)

n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/up…

▾ Sunlitn8n · n8nEPSS 0.36%via NVD
CVE-2026-78583High· 8.1
3w ago

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153)

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used…

▾ Twilightelastic · kibanaEPSS 0.39%via NVD
CVE-2026-82302High· 8.1
3w ago

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

▾ TwilightEPSS 0.39%via NVD
CVE-2026-82299Medium· 6.5
3w ago

Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

▾ SunlitEPSS 0.38%via NVD
CVE-2026-82298Medium· 4.3
3w ago

Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82023Medium· 4.3
3w ago

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a …

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a …

▾ SunlitEPSS 0.29%via NVD
CVE-2026-74769Medium· 6.5
3w ago

Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API

Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-56743Medium· 5.4
3w ago

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.25%via GHSA
GHSA-2q7j-2vhx-56g8High· 8.1
3w ago

OpenClaw Feishu tools could ignore per-account disablement

OpenClaw Feishu tools could ignore per-account disablement

▾ Twilightopenclaw · @openclaw/feishuvia GHSA
GHSA-w8wf-3qvj-6xqfHigh· 8.1
3w ago

OpenClaw Feishu permission tools could ignore per-account disablement

OpenClaw Feishu permission tools could ignore per-account disablement

▾ Twilightopenclaw · @openclaw/feishuvia GHSA
CVE-2026-81165Medium· 5.3
3w ago

Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing

Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.

▾ Sunlitblazy_project · blazyEPSS 0.31%via NVD
CVE-2026-73478Medium· 5.3
3w ago

Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing

Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.

▾ Sunlitdiff_project · diffEPSS 0.31%via NVD
CVE-2026-73477Medium· 5.3
3w ago

Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing

Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.

▾ Sunlitquick_tabs_project · quick_tabsEPSS 0.32%via NVD
CVE-2026-14199High· 7.1
3w ago

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a del…

▾ Twilightgrafana · grafanaEPSS 0.31%via NVD
CVE-2026-77125High· 7.1
3w ago

A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check

A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permissi…

▾ Twilightsonatype · nexus_repository_managerEPSS 0.29%via NVD
CVE-2026-77122Medium· 4.3
3w ago

An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group repository to retrieve …

An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group repository to retrieve …

▾ Sunlitsonatype · nexus_repository_managerEPSS 0.28%via NVD
CVE-2026-84327Medium· 6.5⚖ disputed
3w ago

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.31%via NVD
CWE-863 vulnerabilities (CVEs) — page 12 · VulnSea