VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

874 CVEsRSS

CVE-2026-73290Medium· 5.3
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant falls back to an s3:ListBucket check and…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-73289High· 8.1
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringN…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-73286High· 8.1
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versio…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-73285High· 7.5
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-73265Medium· 6.5
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals wi…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-47231High· 8.1
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking that the actor has `hasUploadRight()` on the URL parameter `folder_uuid`. The `move_save` h…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-71193Critical· 9.6
1mo ago

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a dif…

▾ MidnightEPSS 0.53%via NVD
CVE-2026-68755Medium· 4.3
1mo ago

A bundle writer may create misleading release promotion information under specific conditions.

A bundle writer may create misleading release promotion information under specific conditions.

▾ SunlitEPSS 0.26%via NVD
CVE-2026-64952Medium· 6.5
1mo ago

The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only ass…

The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only ass…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-73499High
1mo ago

etcd is a distributed key-value store for the data of a distributed system

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey() to recei…

▾ Twilightetcd · go.etcd.io/etcd/v3EPSS 0.66%via NVD
CVE-2026-48416High· 7.5
1mo ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitat…

▾ Twilightadobe · commerce_b2bEPSS 0.83%via NVD
CVE-2026-48415High· 7.6
1mo ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and…

▾ Twilightadobe · commerceEPSS 0.46%via NVD
CVE-2026-48412Low· 2.7
1mo ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploita…

▾ Sunlitadobe · commerceEPSS 0.56%via NVD
CVE-2026-48411Medium· 6.5
1mo ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized w…

▾ Sunlitadobe · commerceEPSS 0.63%via NVD
CVE-2026-19550High· 8.2
1mo ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged…

▾ Twilightfreeipa · freeipaEPSS 0.28%via NVD
CVE-2026-71362Critical· 9.1CISA KEVPoC
1mo ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue do…

▾ Hadaladobe · commerceEPSS 88%via NVD
CVE-2026-13738Critical· 9.8
1mo ago

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Web…

▾ Midnightcommvault · commvaultEPSS 0.63%via NVD
CVE-2026-73221None
1mo ago

CVAT is an open source interactive video and image annotation tool for computer vision

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use predictable task-based request IDs with the lambda request retrieve and destroy endpoin…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-63177High· 7.1
1mo ago

Malcolm is a network traffic analysis tool suite

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests usi…

▾ TwilightEPSS 0.30%via NVD
CVE-2026-73213None
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an au…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-73090Critical· 9.3
1mo ago

PeerTube is an ActivityPub-federated video streaming platform

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the h…

▾ MidnightEPSS 0.40%via NVD
CVE-2026-13737Critical· 9.8
1mo ago

CommServe contained an allowlist bypass vulnerability affecting command execution authorization

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Cen…

▾ Midnightcommvault · commvaultEPSS 0.52%via NVD
CVE-2026-63512Medium· 6.5
1mo ago

Microsoft SharePoint Server Tampering Vulnerability

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.73%via CVEORG
CVE-2026-62775Medium· 5.5
1mo ago

Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability

Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 11 version 26H1EPSS 0.35%via CVEORG
CVE-2026-62872High· 8.8
1mo ago

.NET Framework Elevation of Privilege Vulnerability

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft .NET Framework 3.5EPSS 0.78%via CVEORG
CVE-2026-72921High· 8.1
1mo ago

SeaweedFS is a distributed storage system

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling…

▾ Twilightseaweedfs · github.com/seaweedfs/seaweedfsEPSS 0.43%via NVD
CVE-2026-18712High· 8.1
1mo ago

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different col…

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different col…

▾ Twilightmongodb · mongodbEPSS 0.17%via NVD
CVE-2026-18703Medium· 4.2
1mo ago

An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to rest…

An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to rest…

▾ Sunlitmongodb · mongodbEPSS 0.14%via NVD
CVE-2026-18698Medium· 5.4
1mo ago

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of col…

▾ Sunlitmongodb · mongodbEPSS 0.24%via NVD
CVE-2026-18696Medium· 6.5
1mo ago

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do no…

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do no…

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CWE-863 vulnerabilities (CVEs) — page 17 · VulnSea