VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

CVE-2026-53816High· 7.2
2mo ago

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

▾ Twilightopenclaw · openclawEPSS 0.50%via GHSA
GHSA-w5ww-7chg-mxcqHigh
2mo ago

OpenClaw: Telegram interactive callbacks could skip commands.allowFrom

OpenClaw: Telegram interactive callbacks could skip commands.allowFrom

▾ Twilightopenclaw · openclawvia GHSA
GHSA-p73f-w79w-jqr5High
2mo ago

OpenClaw: Native command authorization could skip owner-command enforcement

OpenClaw: Native command authorization could skip owner-command enforcement

▾ Twilightopenclaw · openclawvia GHSA
GHSA-xww8-gqvh-92x9High· 8.0
2mo ago

OpenClaw: Exec approval display truncation could hide the command being approved

OpenClaw: Exec approval display truncation could hide the command being approved

▾ Twilightopenclaw · openclawvia GHSA
GHSA-rggc-m335-3wvjHigh
2mo ago

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-53817High· 8.0
2mo ago

OpenClaw: Control UI locality spoofing could mint a durable admin device token

OpenClaw: Control UI locality spoofing could mint a durable admin device token

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
GHSA-hw9r-h9mr-4jffHigh· 8.8
2mo ago

OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates

OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates

▾ Twilightopenclaw · openclawvia GHSA
GHSA-wv26-j37q-2g7pMedium
2mo ago

OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions

OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-jvm4-4j77-39p6High
2mo ago

OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-56152Medium· 5.3
2mo ago

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1)

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access …

▾ Sunlitelastic · endpoint_securityEPSS 0.30%via NVD
GHSA-fpxg-5xmv-922mMedium· 4.3
2mo ago

SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-6wqw-vhfr-9999Medium· 4.3
2mo ago

SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions

SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-wp87-mgvq-5j93Medium· 6.5
2mo ago

SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization

SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-c8jx-96c9-8xrpMedium· 4.3
2mo ago

SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths

SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-49997Medium· 5.4
2mo ago

SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted

SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted

▾ Sunlitsurrealdb · surrealdbEPSS 0.35%via GHSA
CVE-2026-44935Critical· 9.9
2mo ago

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

▾ Midnightrancher · github.com/rancher/fleetEPSS 0.49%via GHSA
GHSA-98fx-66cf-fc7cMedium· 6.5
2mo ago

SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level

SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-vjjx-rfw4-rmfcMedium· 6.5
2mo ago

SurrealDB: Graph traversal bypasses table SELECT permissions

SurrealDB: Graph traversal bypasses table SELECT permissions

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-6vg3-hgrw-p5gfMedium· 5.4
2mo ago

SurrealDB has an Authorization Bypass via Composite Record-id Paths

SurrealDB has an Authorization Bypass via Composite Record-id Paths

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-49981High
2mo ago

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`

▾ Twilighttwig · twig/twigEPSS 0.36%via GHSA
CVE-2026-53492High· 8.2
2mo ago

github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.35%via CSAF
CVE-2026-49823High· 7.7
2mo ago

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

▾ Twilightfission · github.com/fission/fissionEPSS 0.44%via GHSA
CVE-2026-49824High· 8.5
2mo ago

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

▾ Twilightfission · github.com/fission/fissionEPSS 0.39%via GHSA
CVE-2026-48806Medium
2mo ago

Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys

Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys

▾ Sunlittwig · twig/twigEPSS 0.42%via GHSA
CVE-2026-48807Medium
2mo ago

Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters

Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters

▾ Sunlittwig · twig/twigEPSS 0.37%via GHSA
CVE-2026-48808Medium
2mo ago

Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`

Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`

▾ Sunlittwig · twig/twigEPSS 0.41%via GHSA
CVE-2026-58056High· 7.6
3mo ago

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can …

▾ TwilightEPSS 0.33%via NVD
CVE-2026-13508Medium· 5.5
3mo ago

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation of the argument conversation.agent caus…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-9640High· 7.2
3mo ago

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator i…

▾ Twilightcanonical · lxdEPSS 0.63%via NVD
CVE-2026-49288Medium· 4.3
3mo ago

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

▾ Sunlitstatamic · statamic/cmsEPSS 0.27%via GHSA
CWE-863 vulnerabilities (CVEs) — page 24 · VulnSea