VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

CVE-2026-65015High
2mo ago

n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

▾ Twilightn8n · n8nEPSS 0.61%via GHSA
CVE-2026-65054Low· 3.1
2mo ago

MediaCMS Private Media Metadata Disclosure via Playlist Ownership Loophole

MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media metadata belonging to other users by adding arbitrary media tokens to their own playlist without access control check…

▾ SunlitMediaCMS · MediaCMSEPSS 0.32%via CVEORG
CVE-2026-15829High· 8.1
2mo ago

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, times…

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, times…

▾ Twilightgoogle · mcp_toolbox_for_databasesEPSS 0.18%via NVD
CVE-2026-56144Medium· 5.3
2mo ago

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorize…

▾ Sunlitelastic · elasticsearchEPSS 0.32%via NVD
GHSA-hrxh-6v49-42gfHigh
2mo ago

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

▾ Twilightgrpc · google.golang.org/grpcvia GHSA
CVE-2026-55987High· 8.1
2mo ago

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58427Medium
2mo ago

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-58431Medium· 4.3
2mo ago

Gitea: Public-only API token restriction is not enforced on team API routes

Gitea: Public-only API token restriction is not enforced on team API routes

▾ Sunlitgitea.dev · gitea.devEPSS 0.33%via GHSA
CVE-2026-57897Medium· 6.5
2mo ago

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58440Medium· 6.8
2mo ago

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

▾ Sunlitgitea.dev · gitea.devEPSS 0.48%via GHSA
CVE-2026-59766Medium· 4.3
2mo ago

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

▾ Sunlitgitea · code.gitea.io/giteavia GHSA
CVE-2026-58439High· 8.1
2mo ago

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.53%via GHSA
CVE-2026-56443Medium· 4.3
2mo ago

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / …

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.53%via OSV
CVE-2026-58425Medium· 4.3
2mo ago

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.33%via GHSA
GHSA-rjvx-x5h2-6px5Medium
2mo ago

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

▾ Sunlitgitea · code.gitea.io/giteavia GHSA
CVE-2026-58424High· 8.9PoC
2mo ago

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-58444Medium· 4.3
2mo ago

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-58416Medium· 6.3
2mo ago

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

▾ Sunlitgitea.dev · gitea.devEPSS 0.31%via GHSA
CVE-2026-58417Medium
2mo ago

Gitea: REST API exposes organization membership of private organizations to public

Gitea: REST API exposes organization membership of private organizations to public

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
GHSA-mhm7-754m-9p8wMedium· 6.5
2mo ago

jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`

jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`

▾ Sunlitfasterxml · com.fasterxml.jackson.core:jackson-databindvia GHSA
CVE-2026-44231Critical· 9.1
2mo ago

RT is an open source, enterprise-grade issue and ticket tracking system

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged…

▾ Midnightbestpractical · request_trackerEPSS 0.41%via NVD
CVE-2026-53515High· 7.1
2mo ago

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

▾ Twilightbetter-auth · @better-auth/ssoEPSS 0.43%via GHSA
CVE-2026-54560High· 7.6
2mo ago

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

▾ Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.46%via GHSA
CVE-2026-16215Medium· 6.5
2mo ago

A security flaw has been discovered in geex-arts django-jet up to 1.0.8

A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possibl…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-16200High· 7.3
2mo ago

A vulnerability has been found in zevorn rt-claw up to 0.2.0

A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The manipulation leads to incorrect authorization. Remote expl…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-16197Medium· 6.3
2mo ago

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation l…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-16195Medium· 6.3
2mo ago

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect au…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-10130High· 8.2
2mo ago

QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address

QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unc…

▾ TwilightEPSS 0.56%via NVD
CVE-2026-16126High· 7.3
2mo ago

A vulnerability was determined in zevorn rt-claw up to 0.2.0

A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authori…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-16123Medium· 6.3
2mo ago

A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2

A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation cau…

▾ SunlitEPSS 0.37%via NVD
CWE-863 vulnerabilities (CVEs) — page 21 · VulnSea