VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

874 CVEsRSS

CVE-2026-45121Medium· 4.3
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users to access titles of calendars that are otherwise inaccessible.…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-19670Medium· 5.4
1mo ago

Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g

Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-70657Medium· 4.3
1mo ago

Copyparty is a portable file server

Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the conta…

▾ Sunlitcopyparty · copypartyEPSS 0.33%via NVD
CVE-2026-48508High· 8.8
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION…

▾ Twilightlemur · lemurEPSS 0.33%via NVD
CVE-2026-55163Medium· 6.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(role_id), which allowed either an administrator or any existing member of the target role.…

▾ Sunlitlemur · lemurEPSS 0.22%via NVD
CVE-2026-75480Medium· 6.5
1mo ago

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private m…

▾ Sunlitvolcengine · OpenVikingEPSS 0.41%via NVD
CVE-2026-66792Critical· 9.9
1mo ago

A flaw was found in the multicloud-operators-subscription component

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitatio…

▾ MidnightRed Hat · multicluster-globalhub/multicluster-globalhub-agent-rhel9EPSS 0.69%via NVD
CVE-2026-71424Critical· 9.6
1mo ago

Onyx is an open-source AI platform

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tok…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-71518High· 7.5PoC
1mo ago

Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants

Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute …

▾ MidnightEPSS 0.51%via NVD
CVE-2026-11817Medium· 5.3
1mo ago

CVE-2026-11817 CVE Record

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api…

▾ SunlitGrafana · Grafana OSSEPSS 0.35%via CVEORG
CVE-2026-44846Medium· 6.2
1mo ago

JumpServer is an open source bastion host and an operation and maintenance security audit system

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.invite_user permission can submit an existing member to POST /api/v1/users/users/invite/, causing t…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-19598Critical· 9.8PoC
1mo ago

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funne…

▾ AbyssalEPSS 3.5%via NVD
CVE-2026-74248Medium· 4.3
1mo ago

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments ar…

▾ SunlitEPSS 0.33%via NVD
GHSA-8rw6-p7m8-63jpMedium· 6.5
1mo ago

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-49989Low
1mo ago

CrateDB is a distributed SQL database

CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s…

▾ Sunlitcrate · io.crate:crateEPSS 0.47%via NVD
CVE-2026-73305High· 8.8
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleVali…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-70452High· 7.4
1mo ago

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup f…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.56%via NVD
CVE-2026-19182Medium· 4.3
1mo ago

An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also …

An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also …

▾ SunlitEPSS 0.25%via NVD
CVE-2026-72672High· 7.7
1mo ago

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting us…

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting us…

▾ Twilightelastic · kibanaEPSS 0.38%via NVD
CVE-2026-73841High· 8.8
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:vi…

▾ Twilightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.81%via NVD
CVE-2026-73571Low· 3.1
1mo ago

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP reques…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-73652High
1mo ago

vantage6 is an open-source infrastructure for privacy preserving analysis

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorith…

▾ Twilightvantage6 · vantage6EPSS 0.35%via NVD
CVE-2026-58443Critical· 9.6
1mo ago

code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens (CVE-2026-58443)

A flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integri…

▾ MidnightRed Hat · OpenShift PipelinesEPSS 0.58%via CSAF
CVE-2026-49473High· 8.8
1mo ago

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowi…

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowi…

▾ Twilightcedar-policy · @cedar-policy/authorization-for-expressjsEPSS 0.47%via NVD
CVE-2026-63297Critical· 9.9PoC
1mo ago

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a tar…

▾ Abyssalcanonical · lxdEPSS 0.34%via NVD
CVE-2026-63296Critical· 9.9
1mo ago

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without va…

▾ Midnightcanonical · lxdEPSS 0.44%via NVD
CVE-2026-63295Medium· 4.3
1mo ago

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.…

▾ Sunlitcanonical · lxdEPSS 0.35%via NVD
CVE-2026-62420Critical· 9.9
1mo ago

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member vi…

▾ Midnightcanonical · lxdEPSS 0.54%via NVD
CVE-2026-47230Medium· 6.5
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same root-cause shape as the cross-folder move bug (`05-documents-cross-folder-move-idor.md`): …

▾ SunlitAdmidio · admidioEPSS 0.30%via NVD
CVE-2026-47227Medium· 6.5PoC
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor administers. The follow-up "is this specific categor…

▾ TwilightAdmidio · admidioEPSS 0.33%via NVD
CWE-863 vulnerabilities (CVEs) — page 16 · VulnSea