CWE-863
CVEs classified under CWE-863, newest first.
876 CVEsRSS
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
GHSA-w5ww-7chg-mxcqHighOpenClaw: Telegram interactive callbacks could skip commands.allowFrom
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
GHSA-p73f-w79w-jqr5HighOpenClaw: Native command authorization could skip owner-command enforcement
OpenClaw: Native command authorization could skip owner-command enforcement
GHSA-xww8-gqvh-92x9High· 8.0OpenClaw: Exec approval display truncation could hide the command being approved
OpenClaw: Exec approval display truncation could hide the command being approved
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-53817High· 8.0OpenClaw: Control UI locality spoofing could mint a durable admin device token
OpenClaw: Control UI locality spoofing could mint a durable admin device token
GHSA-hw9r-h9mr-4jffHigh· 8.8OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
GHSA-wv26-j37q-2g7pMediumOpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
GHSA-jvm4-4j77-39p6HighOpenClaw: QQBot streaming command could mutate config without explicit allowFrom
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
CVE-2026-56152Medium· 5.3Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1)
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access …
GHSA-fpxg-5xmv-922mMedium· 4.3SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
GHSA-6wqw-vhfr-9999Medium· 4.3SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
GHSA-wp87-mgvq-5j93Medium· 6.5SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
GHSA-c8jx-96c9-8xrpMedium· 4.3SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
CVE-2026-49997Medium· 5.4SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
CVE-2026-44935Critical· 9.9Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
GHSA-98fx-66cf-fc7cMedium· 6.5SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
GHSA-vjjx-rfw4-rmfcMedium· 6.5SurrealDB: Graph traversal bypasses table SELECT permissions
SurrealDB: Graph traversal bypasses table SELECT permissions
GHSA-6vg3-hgrw-p5gfMedium· 5.4SurrealDB has an Authorization Bypass via Composite Record-id Paths
SurrealDB has an Authorization Bypass via Composite Record-id Paths
CVE-2026-49981HighTwig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
CVE-2026-53492High· 8.2github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…
A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…
CVE-2026-49823High· 7.7Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
CVE-2026-49824High· 8.5Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
CVE-2026-48806MediumTwig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
CVE-2026-48807MediumTwig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
CVE-2026-48808MediumTwig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
CVE-2026-58056High· 7.6RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can …
CVE-2026-13508Medium· 5.5A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28
A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation of the argument conversation.agent caus…
CVE-2026-9640High· 7.2A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.
A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator i…
CVE-2026-49288Medium· 4.3Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources