VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

874 CVEsRSS

CVE-2026-73475Critical· 9.1
3w ago

Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing

Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.

▾ Midnightcentarro · commerce_paypalEPSS 0.40%via NVD
CVE-2026-84332Medium· 5.4
3w ago

chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-84332)

A flaw was found in Google Chrome. This incorrect authorization vulnerability in SiteSettings allows a remote attacker to bypass system access restrictions by enticing a user to visit a specially crafted HTML page. This could lead to unaut…

▾ SunlitRed Hat · ChromeEPSS 0.29%via CSAF
CVE-2026-84206Medium· 4.3
3w ago

Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets

Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset ident…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-84303Medium
3w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are…

▾ Sunlitgrpc · google.golang.org/grpcEPSS 0.31%via NVD
CVE-2026-74994Medium· 6.0
3w ago

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user ad…

▾ SunlitErlang · otpEPSS 0.63%via NVD
CVE-2026-76111High· 8.8
3w ago

Dell PowerStore contains an Incorrect Authorization vulnerability

Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.

▾ TwilightEPSS 0.42%via NVD
CVE-2026-82875Medium· 5.5PoC
3w ago

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can e…

▾ TwilightToolJet · ToolJetEPSS 0.22%via NVD
CVE-2026-50199Medium· 4.3
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential for the authentic…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-82879Medium· 6.3
3w ago

DataEase before 2.10.26 contains multiple access control defects in the sharing link module

DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused against another (ShareTicketManage.validate…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-79746High· 8.1
3w ago

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'c…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-82395Medium
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media …

▾ Sunlitsulu · sulu/suluEPSS 0.43%via NVD
CVE-2026-82394Medium
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforc…

▾ Sunlitsulu · sulu/suluEPSS 0.58%via NVD
CVE-2026-81892High· 8.1
3w ago

EasyAdmin is a fast and modern admin generator for Symfony applications

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuIt…

▾ Twilighteasycorp · easycorp/easyadmin-bundleEPSS 0.45%via NVD
CVE-2026-53552Critical· 9.6
3w ago

Goploy is an open-source automation deployment system

Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id fro…

▾ Midnightzhenorzz · github.com/zhenorzz/goployEPSS 0.35%via NVD
CVE-2026-81643None
4w ago

Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see. In AshGraphql.Subscription.Batcher, do_send/5 resolves the first notification of …

Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see. In AshGraphql.Subscription.Batcher, do_send/5 resolves the first notification of …

▾ SunlitEPSS 0.43%via NVD
CVE-2026-80223None
4w ago

Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver a…

Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver a…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-82634Medium· 6.5
4w ago

Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings

Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings. Attackers with print permissi…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-81318None
4w ago

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a distinct query,…

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a distinct query,…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-81316None
4w ago

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or te…

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or te…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-77454None
4w ago

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing f…

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing f…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-82463High· 8.1
4w ago

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a st…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-77786Medium· 4.9
4w ago

The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify …

The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-77704Low· 2.7
4w ago

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on …

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on …

▾ SunlitEPSS 0.28%via NVD
CVE-2026-82272Medium· 6.5
1mo ago

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and the…

▾ Sunlitimmich-app · immichEPSS 0.44%via NVD
CVE-2026-62904Medium· 5.4
1mo ago

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.39%via NVD
CVE-2026-61783Medium· 6.5
1mo ago

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege user can read the cluster secret from the manager co…

▾ Sunlitwazuh · wazuhEPSS 0.41%via NVD
CVE-2026-55873Medium· 4.3
1mo ago

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

▾ Sunlitseaweedfs · github.com/seaweedfs/seaweedfsEPSS 0.34%via GHSA
CVE-2026-55638High· 8.6
1mo ago

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

▾ Twilight9router · 9routerEPSS 0.61%via GHSA
CVE-2026-55460High· 7.1
1mo ago

Snipe-IT has an authorization bypass on bulk editing users

Snipe-IT has an authorization bypass on bulk editing users

▾ Twilightsnipe · snipe/snipe-itEPSS 0.44%via GHSA
CVE-2026-55472Medium· 4.3
1mo ago

Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.33%via GHSA
CWE-863 vulnerabilities (CVEs) — page 13 · VulnSea