CWE-863
CVEs classified under CWE-863, newest first.
876 CVEsRSS
GHSA-wcr3-9x4c-f5gjHighBlnk has an API key authorization bypass in owner and scope enforcement
Blnk has an API key authorization bypass in owner and scope enforcement
CVE-2026-48794LowAuthelia has an Edge Case Access Control Rule Mismatch
Authelia has an Edge Case Access Control Rule Mismatch
CVE-2026-53521Medium· 6.4Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
CVE-2026-54244Low· 3.5Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
CVE-2026-48776Medium· 4.2LangGraph SDK has unsafe URL path construction
LangGraph SDK has unsafe URL path construction
CVE-2026-49219Medium· 5.5ImageMagick: Policy Bypass can read disallowed files via symlink
ImageMagick: Policy Bypass can read disallowed files via symlink
CVE-2026-56694Medium· 5.4NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups
NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forge…
CVE-2026-49983Medium· 5.2Deno is a JavaScript, TypeScript, and WebAssembly runtime
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --deny-env, or restrict it to a specific allowlist with --allow-env=FOO,BAR. The expectati…
CVE-2026-52808High· 7.1Gogs's write-level collaborators can mutate admin-only repository settings via API
Gogs's write-level collaborators can mutate admin-only repository settings via API
CVE-2026-54518Medium· 6.5jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass (CVE-2026-54518)
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security view restrictions by sending specially crafted JSON (JavaScript Object Notation) data. The UnwrappedPropertyHandler component, which proce…
CVE-2026-54517Medium· 5.3jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application (CVE-2026-54517)
A flaw was found in jackson-databind. A remote attacker can exploit this vulnerability due to an issue in how active-view (@JsonView) filters are applied. Specifically, setterless collections annotated with a restricted @JsonView can be po…
CVE-2026-48493Medium· 5.5Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
CVE-2026-48507High· 7.1Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
CVE-2026-8823Low· 3.8Mattermost has an Incorrect Authorization issue
Mattermost has an Incorrect Authorization issue
CVE-2026-8074Low· 3.8Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
CVE-2026-44911LowApache NiFi allows read-only users to submit component configuration verification request
Apache NiFi allows read-only users to submit component configuration verification request
CVE-2026-41048High· 7.1Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".
CVE-2026-50559High· 7.5Quarkus is a Java framework for building cloud-native applications
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolo…
GHSA-x44p-gg67-52fcMedium· 5.5Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-50008Mediumparse-server: Server option routeAllowList is bypassable through batch sub-requests
parse-server: Server option routeAllowList is bypassable through batch sub-requests
GHSA-xhv3-q4xx-349rHighstistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
GHSA-6gqw-jqv7-v88mHighstigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
GHSA-hv6h-hc26-q48pMedium· 4.3SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
CVE-2026-53843High· 8.8OpenClaw: Pairing-scoped device session could restore revoked node token authority
OpenClaw: Pairing-scoped device session could restore revoked node token authority
CVE-2026-55672High· 7.4ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
GHSA-8579-rgg5-ph2mHigh· 8.8PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
GHSA-qvpf-j64c-jmhrHigh· 8.3PraisonAI Slack app_mention bypasses configured user/channel authorization
PraisonAI Slack app_mention bypasses configured user/channel authorization
GHSA-v847-hxxw-3pxgHigh· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
GHSA-w6h2-fr4q-xvxvHigh· 8.8PraisonAI: Compute-bridged file tools allow shell command injection
PraisonAI: Compute-bridged file tools allow shell command injection
GHSA-4869-x4pr-q22xCritical· 9.8PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass