VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

872 CVEsRSS

CVE-2026-81905Medium· 6.3
2w ago

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alo…

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alo…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.36%via NVD
CVE-2026-85025Critical· 9.8
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow …

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow …

▾ Midnightlangflow · langflowEPSS 0.61%via NVD
CVE-2026-75624High· 8.8
2w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.

▾ Twilightibm · app_connect_enterpriseEPSS 0.50%via NVD
CVE-2026-88044Critical· 9.1PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 const…

▾ Abyssalrclone · rcloneEPSS 0.56%via NVD
CVE-2026-88884Medium· 5.8
2w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updat…

▾ Sunlitrenovatebot · renovateEPSS 0.30%via NVD
CVE-2026-88894Medium· 5.4PoC
2w ago

Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target

Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\Predefine…

▾ Twilightgrokability · snipe-itEPSS 0.26%via NVD
CVE-2026-88006Medium· 6.5
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role managem…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-88005Medium· 6.5
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allow…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-87090High· 8.3
2w ago

Consul vulnerable to an authorization bypass in the catalog node-write path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker wit…

▾ TwilightHashiCorp · ConsulEPSS 0.37%via CVEORG
CVE-2026-87107Medium· 5.4
2w ago

Consul vulnerable to an authorization bypass in the catalog deregistration path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permiss…

▾ SunlitHashiCorp · ConsulEPSS 0.31%via CVEORG
CVE-2026-88939High· 8.3PoC
2w ago

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project direct…

▾ Midnightknowns-dev · knownsEPSS 0.48%via NVD
CVE-2026-88008Critical· 9.1⚖ disputed
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backen…

▾ Midnighttraefik · traefikEPSS 0.49%via NVD
CVE-2026-88007Critical· 9.1
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport …

▾ Midnighttraefik · traefikEPSS 0.60%via NVD
CVE-2026-88862High· 8.8PoC
2w ago

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied num…

▾ MidnightCap-go · capgo.appEPSS 0.44%via NVD
CVE-2026-88860Medium· 6.3
2w ago

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked…

▾ SunlitCap-go · capgo.appEPSS 0.27%via NVD
CVE-2026-87803High· 7.1
2w ago

An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer

An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it thr…

▾ TwilightCountly · countly-serverEPSS 0.31%via NVD
CVE-2026-19840Medium· 6.5
2w ago

The Notiqoo WordPress plugin before 1.4.14 does not have capability checks on several of its AJAX actions and builds the name of the option to write from user input, allowing users with a role as low as contributor to modify arbitrary W…

The Notiqoo WordPress plugin before 1.4.14 does not have capability checks on several of its AJAX actions and builds the name of the option to write from user input, allowing users with a role as low as contributor to modify arbitrary W…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-86760Medium· 5.4PoC
2w ago

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update()

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload befo…

▾ Twilightsnipeitapp · snipe-itEPSS 0.38%via NVD
CVE-2026-86755Medium· 5.4
2w ago

Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission ga…

Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission ga…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.27%via NVD
CVE-2026-86750High· 7.7
2w ago

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and …

▾ Twilightsnipeitapp · snipe-itEPSS 0.33%via NVD
CVE-2026-86773Medium· 5.4PoC
2w ago

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The existing check authoriz…

▾ Twilightsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-87017Medium· 4.3
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filter, but the searc…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-61910Low· 3.5
2w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annot…

▾ Sunlitcyrus · imapEPSS 0.19%via NVD
CVE-2026-86747Medium· 5.4
2w ago

Snipe-IT is an open source IT asset management system

Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /repo…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-46460Low· 3.5
2w ago

Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability

Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially e…

▾ Sunlitdell · powerscale_onefsEPSS 0.18%via NVD
CVE-2026-87998High· 7.1
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge bas…

▾ Twilightopenwebui · open_webuiEPSS 0.49%via NVD
CVE-2026-87014Medium· 6.5PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's d…

▾ Twilightopenwebui · open_webuiEPSS 0.51%via NVD
CVE-2026-86754High· 7.3
2w ago

Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs

Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into app…

▾ Twilightsnipeitapp · snipe-itEPSS 0.34%via NVD
CVE-2026-86752Medium· 5.4
2w ago

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permi…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-85978Critical· 9.8
2w ago

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to …

▾ MidnightPerforce · AkanaEPSS 1.4%via NVD
CWE-863 vulnerabilities (CVEs) — page 8 · VulnSea