VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

872 CVEsRSS

CVE-2023-50460Medium· 5.4
1w ago

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any f…

▾ SunlitTYPO3 · femanagerEPSS 0.24%via NVD
CVE-2023-45023Medium· 4.2
1w ago

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

▾ SunlitTYPO3 · femanagerEPSS 0.14%via NVD
CVE-2026-72524High· 8.8
1w ago

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 …

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 …

▾ TwilightApache Software Foundation · Apache DorisEPSS 0.47%via NVD
CVE-2026-68570Medium· 6.5
1w ago

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This issue affects Apa…

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This issue affects Apa…

▾ SunlitApache Software Foundation · Apache DorisEPSS 0.38%via NVD
CVE-2026-20773High· 8.5
1w ago

A role-based access control issue was identified in the administrative expression evaluation functionality

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissi…

▾ TwilightPing Identity · PingFederateEPSS 0.21%via NVD
CVE-2026-90934Medium· 4.3
1w ago

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by ex…

▾ Sunlitespocrm · espocrmEPSS 0.30%via NVD
CVE-2026-90929High· 8.1
1w ago

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go)

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a tar…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVE-2026-77181Critical· 9.8
1w ago

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update opera…

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update opera…

▾ MidnightApache Software Foundation · org.apache.syncope.core.am:syncope-core-am-logicEPSS 0.51%via NVD
CVE-2026-73668Critical· 9.8
1w ago

Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another…

Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another…

▾ MidnightApache Software Foundation · org.apache.syncope.core.idm:syncope-core-idm-logicEPSS 0.51%via NVD
CVE-2026-73579Critical· 9.8
1w ago

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such trans…

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such trans…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-commonEPSS 0.51%via NVD
CVE-2023-50462Medium· 5.3
1w ago

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to…

▾ SunlitTYPO3 · content_consentEPSS 0.27%via NVD
CVE-2026-82432High· 8.1
1w ago

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validat…

▾ TwilightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.37%via NVD
CVE-2026-82431Critical· 9.8
1w ago

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.us…

▾ MidnightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.39%via NVD
CVE-2026-82920Medium· 5.5
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC …

▾ SunlitMattermost · MattermostEPSS 0.26%via NVD
CVE-2026-73370Critical· 9.8
1w ago

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate en…

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate en…

▾ MidnightApache Software Foundation · org.apache.syncope.core.idm:syncope-core-idm-logicEPSS 0.51%via NVD
CVE-2026-73236High· 7.5
1w ago

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches. Due to incorrect implementation, two sibling Realms whose names begin with…

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches. Due to incorrect implementation, two sibling Realms whose names begin with…

▾ TwilightApache Software Foundation · Apache SyncopeEPSS 0.36%via NVD
CVE-2023-50459Medium· 5.4
1w ago

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend user…

▾ SunlitTYPO3 · femanagerEPSS 0.42%via NVD
CVE-2026-54180High· 7.6
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder …

▾ TwilightLaravel-Backpack · CRUDEPSS 0.46%via NVD
CVE-2026-56839High· 7.3PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy w…

▾ MidnightMervinPraison · PraisonAIEPSS 0.38%via NVD
CVE-2026-57125Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.60%via NVD
CVE-2026-55866Low· 3.7
1w ago

SpiceDB is an open source database system for creating and managing security-critical application permissions

SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or…

▾ Sunlitauthzed · spicedbEPSS 0.34%via NVD
CVE-2026-90508Low· 3.4PoC
2w ago

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Pe…

▾ TwilightChengdu Qilu Technology · LudashiEPSS 0.16%via NVD
CVE-2026-90595Medium· 6.3PoC
2w ago

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation res…

▾ Twilightwxiaoqi · Spring-Cloud-PlatformEPSS 0.37%via NVD
CVE-2026-90594Medium· 6.3PoC
2w ago

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Servic…

▾ Twilightwxiaoqi · Spring-Cloud-PlatformEPSS 0.37%via NVD
CVE-2026-89267Medium· 4.3
2w ago

starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields

starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter quer…

▾ Sunlitjowilf · starlette-adminEPSS 0.33%via NVD
CVE-2026-89151Low· 3.5
2w ago

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

▾ SunlitForgejo · ForgejoEPSS 0.23%via NVD
CVE-2026-90460High· 7.6PoC
2w ago

An issue was discovered in OpenStack Keystone before 29.0.3

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or d…

▾ MidnightOpenStack · KeystoneEPSS 0.55%via NVD
CVE-2026-90450Medium· 5.3
2w ago

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered…

▾ SunlitCISA · MalcolmEPSS 0.35%via NVD
CVE-2026-78134High· 7.1
2w ago

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

▾ Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-89013High· 7.5PoC
2w ago

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can…

▾ MidnightDolibarr · DolibarrEPSS 0.50%via NVD
CWE-863 vulnerabilities (CVEs) — page 7 · VulnSea