VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

CVE-2026-67439Medium· 4.3
1mo ago

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

▾ SunlitOliveTin · github.com/OliveTin/OliveTinEPSS 0.43%via GHSA
CVE-2026-16751Medium· 6.5
2mo ago

Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and ta…

Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and ta…

▾ SunlitEnte · Museum ServerEPSS 0.42%via NVD
CVE-2026-18255High· 7.2
2mo ago

A flaw was found in Quay

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot …

▾ TwilightRed Hat · quay/quay-rhel8EPSS 0.65%via NVD
CVE-2026-54693High
2mo ago

ZITADEL Users Can Self-Verify Email/Phone via API

ZITADEL Users Can Self-Verify Email/Phone via API

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.58%via GHSA
CVE-2026-54719High· 7.5
2mo ago

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

▾ Twilightpatrickhener · github.com/patrickhener/goshsEPSS 0.47%via GHSA
CVE-2026-66064Medium· 5.3
2mo ago

goshs has ACL Bypass & Path Traversal

goshs has ACL Bypass & Path Traversal

▾ Sunlitpatrickhener · github.com/patrickhener/goshs/v2EPSS 0.45%via GHSA
CVE-2026-42016High· 8.1CISA KEVPoC
2mo ago

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

▾ Abyssaljfrog · artifactoryEPSS 8.6%via CVEORG
GHSA-47w6-gwp4-w6vcHigh
2mo ago

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

▾ Twilightvantage6 · vantage6via GHSA
GHSA-v6w6-358x-2433Medium· 5.4
2mo ago

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GHSA-xg4h-6gfc-h4m8High
2mo ago

etcd: Watch API authorization bypass via open-ended range requests

etcd: Watch API authorization bypass via open-ended range requests

▾ Twilightetcd · go.etcd.io/etcd/v3via GHSA
CVE-2026-59212Medium· 5.4
2mo ago

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

▾ Sunlitopen-webui · open-webuiEPSS 0.42%via GHSA
GHSA-j9fc-w3mr-x6mvHigh· 8.8
2mo ago

Budibase: Privilege escalation via public role assignment API missing app-level authorization

Budibase: Privilege escalation via public role assignment API missing app-level authorization

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-xcx6-4f2g-hhgxHigh· 7.7
2mo ago

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

▾ Twilightbudibase · @budibase/servervia GHSA
CVE-2026-59226Low· 3.1
2mo ago

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

▾ Sunlitopen-webui · open-webuiEPSS 0.53%via GHSA
CVE-2026-59227Medium· 4.3
2mo ago

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

▾ Sunlitopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-59217Medium· 4.3
2mo ago

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
GHSA-h3rm-78g3-j7cpHigh· 7.1
2mo ago

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

▾ Twilightbetter-auth · @better-auth/stripevia GHSA
GHSA-56m6-8q75-f2rwMedium· 4.7
2mo ago

ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219

ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-15630Critical· 9.9PoC
2mo ago

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

▾ AbyssalCasdoor · CasdoorEPSS 0.34%via NVD
CVE-2026-13060Medium· 6.5
2mo ago

$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and …

▾ SunlitMongoDB · MongoDB ServerEPSS 0.40%via CVEORG
GHSA-h5v5-8746-g7mmMedium
2mo ago

JupyterLab PluginManager lock-rule enforcement bypass

JupyterLab PluginManager lock-rule enforcement bypass

▾ Sunlitjupyterlab · jupyterlabvia OSV
GHSA-5vfw-jc4p-fj39Medium
2mo ago

Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

▾ Sunlitn8n · n8nvia GHSA
GHSA-88c4-pcqm-3r9pMedium
2mo ago

Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

▾ Sunlitn8n · n8nvia GHSA
GHSA-6qc9-mqvw-jg7xHigh
2mo ago

n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

▾ Twilightn8n · n8nvia GHSA
GHSA-cj9h-qx8g-pq2gHigh
2mo ago

n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON

n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON

▾ Twilightn8n · n8nvia GHSA
CVE-2026-65594Medium
2mo ago

n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

▾ Sunlitn8n · n8nEPSS 0.44%via GHSA
CVE-2026-65596Medium
2mo ago

n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

▾ Sunlitn8n · n8nEPSS 0.37%via GHSA
GHSA-8342-988q-86crHigh
2mo ago

n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login

n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login

▾ Twilightn8n · n8nvia GHSA
GHSA-64xh-79j6-r5v8High
2mo ago

n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes

n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes

▾ Twilightn8n · n8nvia GHSA
GHSA-w46p-w7w2-fr9gHigh
2mo ago

Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool

Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool

▾ Twilightn8n · n8nvia GHSA
CWE-863 vulnerabilities (CVEs) — page 20 · VulnSea