VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

871 CVEsRSS

CVE-2026-92403Low· 3.7
1w ago

The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different regis…

The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different regis…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-11540Medium· 5.3
1w ago

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.30%via NVD
GHSA-xwmw-prc4-v3crHigh· 8.8
1w ago

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

▾ Twilightobot-platform · github.com/obot-platform/obotvia OSV
GHSA-pr6h-vr44-xq8jMedium· 5.3
1w ago

Obot: MCP Registry API readable without authentication

Obot: MCP Registry API readable without authentication

▾ Sunlitobot-platform · github.com/obot-platform/obotvia OSV
CVE-2026-81178Low· 3.5
1w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share consumer joins the same c…

▾ SunlitSyslifters · sysreptorEPSS 0.30%via NVD
CVE-2026-61672High· 7.1PoC
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assume…

▾ Midnightprojectcapsule · capsuleEPSS 0.33%via NVD
CVE-2026-93594High· 8.1PoC
1w ago

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or th…

▾ MidnightArcadeData · arcadedbEPSS 0.44%via NVD
CVE-2026-93593High· 8.1PoC
1w ago

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privil…

▾ MidnightArcadeData · arcadedbEPSS 0.36%via NVD
CVE-2026-75157High· 7.5PoC
1w ago

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently sup…

▾ MidnightApache Software Foundation · apache-airflowEPSS 0.44%via NVD
CVE-2026-68791High· 8.6
1w ago

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

▾ Twilightmicrosoft · azure_machine_learningEPSS 0.99%via NVD
CVE-2026-93379Medium· 4.3
1w ago

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-92992Medium· 6.3PoC
1w ago

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authoriza…

▾ TwilightDromara · mayfly-goEPSS 0.39%via NVD
CVE-2026-92904Medium· 4.3
1w ago

A flaw was found in the foreman_remote_execution plugin's template invocations controller

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filt…

▾ SunlitRed Hat · rubygem-foreman_remote_executionEPSS 0.34%via NVD
CVE-2026-92611Medium· 4.8
1w ago

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

▾ SunlitEclipse Foundation · Eclipse AnkaiosEPSS 0.30%via NVD
CVE-2026-92893Medium· 4.3
1w ago

A flaw was found in the foreman_ansible plugin's Ansible inventory API

A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An…

▾ SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.28%via NVD
CVE-2026-81439Low· 3.7
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechani…

▾ SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.19%via NVD
CVE-2026-78426Low· 3.7
1w ago

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equ…

▾ Sunlitgo · neuvectorEPSS 0.19%via NVD
CVE-2026-92894Medium· 4.3
1w ago

A flaw was found in the foreman_ansible plugin's Ansible override values API

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authent…

▾ SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.26%via NVD
CVE-2026-90923Medium· 6.5
1w ago

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

▾ SunlitEPSS 0.27%via NVD
CVE-2026-92760Medium· 6.5PoC
1w ago

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info end…

▾ Twilightshlinkio · shlinkEPSS 0.41%via NVD
CVE-2026-92764Medium· 4.3
1w ago

OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships

OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve ev…

▾ Sunlitopencve · opencveEPSS 0.37%via NVD
CVE-2026-92771Medium· 6.5PoC
1w ago

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue…

▾ Twilighttwentyhq · twentyEPSS 0.44%via NVD
CVE-2026-92774Medium· 4.3PoC
1w ago

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve…

▾ Twilightrequarks · Wiki.jsEPSS 0.37%via NVD
CVE-2026-92776High· 8.1PoC
1w ago

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated …

▾ Midnightrequarks · Wiki.jsEPSS 0.45%via NVD
CVE-2026-92782High· 8.1PoC
1w ago

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, a…

▾ Midnightchroma-core · chromaEPSS 0.45%via NVD
CVE-2026-92788High· 8.8
1w ago

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against oth…

▾ Twilightcoze-dev · coze-studioEPSS 0.52%via NVD
CVE-2026-92793High· 8.1
1w ago

GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter

GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the adm…

▾ TwilightGoAdminGroup · go-adminEPSS 0.45%via NVD
CVE-2026-92801High· 8.8
1w ago

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the p…

▾ Twilightchenhg5 · cc-connectEPSS 0.55%via NVD
CVE-2026-92796High· 8.8PoC
1w ago

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements a…

▾ Midnightmanticoresoftware · Manticore SearchEPSS 0.52%via NVD
CVE-2026-86043High· 7.5PoC
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent beca…

▾ Midnightzalando · skipperEPSS 0.45%via NVD
CWE-863 vulnerabilities (CVEs) — page 4 · VulnSea