VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

CVE-2026-20706Medium
3mo ago

Gitea: Token scope bypass on web archive download endpoint

Gitea: Token scope bypass on web archive download endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.56%via GHSA
CVE-2026-48489High
3mo ago

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

▾ Twilightsymfony · symfony/security-httpEPSS 0.60%via GHSA
CVE-2026-54281High
3mo ago

Nest: Middleware Bypass on Fastify via Trailing Slash

Nest: Middleware Bypass on Fastify via Trailing Slash

▾ Twilightnestjs · @nestjs/platform-fastifyEPSS 0.50%via GHSA
CVE-2026-48152High· 8.1
3mo ago

Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL

Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL

▾ Twilightbudibase · @budibase/serverEPSS 0.44%via GHSA
CVE-2026-54091High· 7.5
3mo ago

File Browser has incorrect access control for public directory shares via rule path rebasing

File Browser has incorrect access control for public directory shares via rule path rebasing

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.52%via GHSA
CVE-2026-48089High
3mo ago

DevGuard has improper authorization on public assets

DevGuard has improper authorization on public assets

▾ Twilightl3montree-dev · github.com/l3montree-dev/devguardEPSS 0.36%via GHSA
CVE-2026-48860Medium· 6.5
3mo ago

Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The inet_tls_dist:check_ip/1 function, which enforces a LAN allow…

Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The inet_tls_dist:check_ip/1 function, which enforces a LAN allow…

▾ Sunliterlang · erlang/otpEPSS 0.38%via NVD
CVE-2026-0272High· 7.2
3mo ago

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk…

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk…

▾ Twilightpaloaltonetworks · pan-osEPSS 0.26%via NVD
CVE-2026-49397Medium· 5.3
3mo ago

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.34%via GHSA
CVE-2026-47929High· 8.4
3mo ago

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vuln…

▾ Twilightadobe · coldfusionEPSS 0.45%via NVD
CVE-2026-41852Low· 3.7
3mo ago

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic.…

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic.…

▾ Sunlitvmware · spring_frameworkEPSS 0.26%via NVD
CVE-2026-34507Medium· 5.4
4mo ago

OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or conte…

▾ SunlitOpenClaw · OpenClawEPSS 0.25%via CVEORG
CVE-2026-35674High· 8.8
4mo ago

OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external…

▾ TwilightOpenClaw · OpenClawEPSS 0.45%via CVEORG
CVE-2026-35673Medium· 6.5
4mo ago

OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes

OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can bypass private-network SSRF policies by r…

▾ SunlitOpenClaw · OpenClawEPSS 0.26%via CVEORG
CVE-2026-44832High· 8.8
4mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]…

▾ Twilightsnipeitapp · snipe-itEPSS 0.44%via NVD
CVE-2026-39828Medium· 6.3⚖ disputed
4mo ago

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succee…

▾ Sunlitgolang.org/x/crypto · golang.org/x/crypto/sshEPSS 0.54%via CVEORG
CVE-2026-46595High· 7.1PoC⚖ disputed
4mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)

A flaw was found in golang.org/x/crypto/ssh. Source-address validation can be skipped when an SSH server configuration uses an authentication callback type other than public key, allowing authorization bypass in misconfigured servers. This…

▾ MidnightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.60%via CSAF
CVE-2026-47102High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user…

▾ Midnightlitellm · litellmEPSS 0.82%via NVD
CVE-2026-47101High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified route…

▾ Midnightlitellm · litellmEPSS 1.3%via NVD
CVE-2026-20238Medium· 6.5
4mo ago

In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app conta…

In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app conta…

▾ Sunlitsplunk · ai_toolkitEPSS 0.32%via NVD
CVE-2026-42526Medium· 5.3
4mo ago

In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve a `conn_id` containing a `/` (e.g

In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve a `conn_id` containing a `/` (e.g. `"my_team/conn"`) to the same path as anoth…

▾ Sunlitapache · airflow_providers_amazonEPSS 0.54%via NVD
CVE-2026-43999Critical· 9.9
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads …

▾ Midnightvm2_project · vm2EPSS 0.97%via NVD
CVE-2026-44573High· 7.5
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized acc…

▾ Twilightvercel · next.jsEPSS 0.76%via NVD
CVE-2026-2725Medium· 5.3
4mo ago

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restrict…

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restrict…

▾ Sunlitgoogle · gerritEPSS 0.16%via NVD
CVE-2026-34646High· 7.5
4mo ago

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this…

▾ Twilightadobe · commerceEPSS 0.73%via NVD
CVE-2026-34645High· 7.5
4mo ago

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this…

▾ Twilightadobe · commerceEPSS 0.73%via NVD
CVE-2026-34660Critical· 9.3
4mo ago

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabil…

▾ Midnightadobe · connect_desktop_applicationEPSS 1.0%via NVD
CVE-2026-44221Critical· 9.0
4mo ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two …

▾ MidnightEPSS 0.43%via NVD
CVE-2026-39852High· 8.2
4mo ago

Quarkus is a Java framework for building cloud-native applications

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allo…

▾ Twilightquarkus · quarkusEPSS 0.63%via NVD
CVE-2026-30368Medium· 5.4PoC
5mo ago

A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthor…

A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthor…

▾ TwilightLightspeed · Lightspeed ClassroomEPSS 0.34%via NVD
CWE-863 vulnerabilities (CVEs) — page 27 · VulnSea