VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

CVE-2026-16122Medium· 4.3
2mo ago

A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2

A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-16119Medium· 6.3
2mo ago

A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2

A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in i…

▾ SunlitEPSS 0.40%via NVD
CVE-2025-71390None
2mo ago

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions

SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames against --deny-net network access restrictions in its http::* functions. An authenticated user can invoke http::<fn>(<url>)…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-47866High· 8.3
2mo ago

VMware Avi Load Balancer contains an authorization bypass vulnerability

VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-62228High· 8.8
2mo ago

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attack…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-62223High· 8.8
2mo ago

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-62217High· 8.8
2mo ago

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyon…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-62209High· 8.1
2mo ago

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-62202High· 8.8
2mo ago

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intende…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-62290High· 7.3
2mo ago

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 until 1.19.6 and 1.20.3, Challenge resources und…

▾ TwilightEPSS 0.11%via NVD
GHSA-48qw-824m-86prHigh· 7.7
2mo ago

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

▾ Twilightarcadedb · com.arcadedb:arcadedb-servervia GHSA
CVE-2026-59258High· 8.3PoC
2mo ago

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can dem…

▾ Midnightimmich-app · immichEPSS 0.46%via NVD
CVE-2026-59889Medium· 6.5
2mo ago

com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties (CVE…

A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to w…

▾ SunlitRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.39%via CSAF
CVE-2026-47303High· 8.8
2mo ago

ASP.NET Core Elevation of Privilege Vulnerability

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.84%via CVEORG
CVE-2026-50528High· 8.2
2mo ago

.NET Security Feature Bypass Vulnerability

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.61%via CVEORG
CVE-2026-15641High· 7.1
2mo ago

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpo…

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpo…

▾ Twilightdevolutions · devolutions_serverEPSS 0.29%via NVD
CVE-2026-55608Medium· 4.2
2mo ago

n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode

n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode

▾ Sunlitn8n-mcp · n8n-mcpEPSS 0.28%via GHSA
CVE-2026-62196High· 8.3
2mo ago

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authoriza…

▾ Twilightopenclaw · openclawEPSS 0.40%via NVD
CVE-2026-10106Medium· 6.5
2mo ago

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a pri…

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a pri…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-15541High· 7.3
2mo ago

A flaw has been found in will-moss Isaiah up to 1.36.9

A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent …

▾ TwilightEPSS 0.54%via NVD
CVE-2026-15507Medium· 6.3
2mo ago

A vulnerability was detected in coollabsio Coolify up to 4.1.1

A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote ex…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-61874Low· 3.1
2mo ago

filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind

filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a traili…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-56252Medium· 5.4
2mo ago

Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations

Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. Attackers with app-scoped credentials can trigger signed outbound…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-1359High· 8.8
2mo ago

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes…

▾ TwilightEPSS 0.44%via NVD
CVE-2026-13238None
2mo ago

Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing

Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.

▾ SunlitEPSS 0.22%via NVD
CVE-2026-13237None
2mo ago

Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing

Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.

▾ SunlitEPSS 0.22%via NVD
CVE-2026-13232None
2mo ago

Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing

Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.

▾ SunlitEPSS 0.21%via NVD
CVE-2026-57218None
2mo ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing cons…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-57217None
2mo ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors fro…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-57215None
2mo ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route t…

▾ SunlitEPSS 0.38%via NVD
CWE-863 vulnerabilities (CVEs) — page 22 · VulnSea