VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

874 CVEsRSS

CVE-2026-79258Medium· 6.5
1mo ago

Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page

Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.32%via CVEORG
CVE-2026-49050High· 8.8
1mo ago

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

▾ Twilightapache · dolphinschedulerEPSS 0.58%via NVD
CVE-2026-80182None
1mo ago

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and …

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and …

▾ SunlitEPSS 0.57%via NVD
GHSA-mf8r-wm2w-f8c5Medium· 5.3
1mo ago

phpMyFAQ public FAQ APIs expose inactive FAQ content

phpMyFAQ public FAQ APIs expose inactive FAQ content

▾ Sunlitthorsten · thorsten/phpmyfaqvia GHSA
CVE-2026-76836High· 8.8
1mo ago

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-67204Medium· 5.4
1mo ago

BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions …

BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions …

▾ SunlitEPSS 0.41%via NVD
CVE-2026-71510Medium· 6.5
1mo ago

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses with…

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses with…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-71506High· 8.1
1mo ago

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the i…

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the i…

▾ TwilightEPSS 0.54%via NVD
GHSA-vx2m-jpxr-xv7wMedium· 5.3
1mo ago

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
CVE-2026-62382NonePoC
1mo ago

PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic

PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil…

▾ TwilightEPSS 1.1%via NVD
CVE-2026-60083Medium· 4.9
1mo ago

SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API

SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode pa…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-4245Medium· 4.3
1mo ago

The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11

The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capab…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-62941Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged …

▾ MidnightEPSS 0.44%via NVD
CVE-2026-62313Medium· 4.3
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared host idm…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-59318Medium· 6.5
1mo ago

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current…

▾ Sunlitvmware · spring_aiEPSS 0.25%via NVD
CVE-2026-69555Critical· 10.0
1mo ago

Azure Arc Elevation of Privilege Vulnerability

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure ARCEPSS 0.80%via CVEORG
GHSA-fm29-4mq3-phg6Medium· 5.3
1mo ago

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
CVE-2026-54136Medium
1mo ago

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.715.0, a resource-scoped API token could read script contents outside its allowed path scope through GET /api/w/{worksp…

▾ Sunlitwindmill-api · windmill-apiEPSS 0.47%via NVD
CVE-2026-50173None
1mo ago

Flow-Like is a platform for building end-to-end use cases

Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/presign` grants Azure Blob Storage SAS credentials with write and delete access to app content to any app member that ha…

▾ SunlitEPSS 0.68%via NVD
CVE-2026-68561High· 8.8
1mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldName…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-55089Critical· 9.9
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check…

▾ MidnightEPSS 0.46%via NVD
CVE-2026-55643None
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUse…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-54742None
1mo ago

Lemmy is a link aggregator and forum for the fediverse

Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in other communities through federated CollectionAdd and CollectionRemove activit…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-41424High· 8.2
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") inst…

▾ Twilightwazuh · wazuhEPSS 0.47%via NVD
CVE-2026-44252High· 8.8
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from …

▾ Twilightwazuh · wazuhEPSS 0.54%via NVD
CVE-2026-76238High
1mo ago

stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all te…

stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all te…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.36%via NVD
CVE-2026-49976Medium· 6.5
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. …

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.47%via NVD
CVE-2026-50550Medium· 5.8
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.27%via NVD
CVE-2026-61574High· 8.8
1mo ago

authentik is an open-source identity provider

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and …

▾ TwilightEPSS 0.62%via NVD
CVE-2026-45122Medium· 4.3
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation permission for the source calendar can mov…

▾ SunlitEPSS 0.34%via NVD
CWE-863 vulnerabilities (CVEs) — page 15 · VulnSea