By weakness (CWE)
CWE-285: related vulnerabilities
CVEs classified under CWE-285. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
44 published vulnerabilities
- CVE-2026-46656HIGH 8.8
Bludit, a content management system, has a critical flaw in how it manages user sessions. When an administrator deletes a user account from the database, the system fails to invalidate that user's active login sessions. This means a deleted user can continue accessing the CMS with full privileges as if their account still existed—a "ghost session" vulnerability. The flaw affects all Bludit versions before 3.22.0 and is fixed in that release.
- CVE-2026-45503HIGH 8.1
CVE-2026-45503 is a HIGH severity vulnerability in Microsoft Exchange Server that allows an already-authenticated attacker to access sensitive information over the network without user interaction. The flaw stems from improper authorization controls—meaning the server fails to properly verify what an authorized user should be allowed to see. An attacker with valid Exchange credentials can exploit this to read data they shouldn't have access to, such as emails, calendar entries, or other mailbox contents.
- CVE-2026-46484HIGH 8.1
Headplane, a web interface for managing Headscale VPN infrastructure, contains a path traversal and authorization bypass flaw in how it handles node and user rename operations. An authenticated attacker can exploit this to access or modify resources they should not be permitted to touch, potentially affecting the integrity and availability of the VPN management system. Versions 0.6.3 and 0.7.0-beta.3 contain the fix.
- CVE-2026-47740HIGH 8.1
Shopper is a headless e-commerce admin panel that manages orders and payments. Before version 2.8.0, the application had a critical permission bypass flaw: users with read-only access to orders could perform actions meant only for administrators with edit permissions. This included canceling orders, marking them as paid or complete, capturing payments from customer credit cards, and modifying shipment tracking. A low-privilege employee or attacker with basic read access could therefore manipulate any order's lifecycle and trigger real financial transactions without authorization.
- CVE-2026-47298HIGH 8.0
CVE-2026-47298 is a high-severity authorization flaw in Microsoft SharePoint Server that allows an authenticated attacker to execute arbitrary code on affected systems over the network. While the attacker must already have valid credentials, the vulnerability bypasses intended access controls, enabling privilege escalation or lateral movement within an organization. User interaction is required to trigger the exploit, which limits but does not eliminate risk in environments where phishing or social engineering are viable attack vectors.
- CVE-2026-0072HIGH 7.8
A missing permission check in Android's input method manager allows a local attacker with minimal privileges to escalate their access and take full control of the affected device. No user action is required to exploit this flaw, making it a practical risk in multi-user or compromised environments.
- CVE-2026-42902HIGH 7.8
Microsoft PowerToys contains an authorization flaw that allows someone with local access and a valid account on a system to gain elevated privileges. An attacker who already has user-level credentials can exploit this design weakness to obtain higher-level permissions, potentially taking full control of the affected system. The vulnerability requires local access and legitimate user credentials to trigger, limiting exposure but creating a meaningful risk in shared or multi-tenant environments.
- CVE-2026-45490HIGH 7.8
A flaw in Microsoft .NET allows an authorized local user to bypass privilege restrictions and gain higher-level access on the same machine. An attacker who already has login credentials can exploit this improper authorization logic to escalate to administrative or system-level permissions, potentially compromising the entire system.
- CVE-2026-10236HIGH 7.3
A security flaw exists in SourceCodester Water Billing Management System version 1.0 that allows attackers to bypass authorization controls in the User Management system. An attacker can remotely manipulate user-related operations through the /classes/Users.php?f=save endpoint without needing credentials or user interaction. This means an unauthorized person could potentially create, modify, or access user accounts and associated data. Public disclosure of this vulnerability means attackers are likely already aware of and testing for it.
- CVE-2026-11462HIGH 7.3
BeikeShop, an e-commerce platform by Chengdu Everbrite Network Technology, contains an authorization flaw in its Stripe payment plugin that allows unauthenticated attackers to manipulate request parameters and gain unauthorized access to sensitive functions. The vulnerability affects versions up to 1.6.0.22 and has been publicly disclosed, increasing exploitation risk. A patch is available and should be deployed promptly.
- CVE-2026-10272MEDIUM 6.5
A4M4's Student-Management-System contains an authorization flaw in its admin panel that allows unauthenticated attackers to manipulate a parameter called 'sid' in the deleteform.php file, potentially leading to unauthorized data modification or deletion. The vulnerability is network-accessible and does not require user interaction or special privileges to exploit. While the issue has been publicly disclosed and exploit code is available, the development team has not yet issued a patch or formal response.
- CVE-2026-45275MEDIUM 6.5
A vulnerability in Nextcloud's Approval app allows users to bypass permission controls and force files to be shared with approvers, even when they lack sharing rights. An attacker with basic user credentials can exploit this to distribute restricted files without authorization. Nextcloud addressed this in version 2.7.2.
- CVE-2026-10211MEDIUM 6.3
AstrBot version 4.23.6 contains a flaw in how it validates file system paths, allowing authenticated users to bypass access restrictions and read, modify, or delete files they shouldn't be able to access. An attacker with valid credentials can exploit this remotely without user interaction. The vulnerability has already been disclosed publicly, and exploit code may be available.
- CVE-2026-10212MEDIUM 6.3
A flaw in AstrBot version 4.24.2 allows an authenticated attacker to manipulate the session_id parameter in the astr_main_agent function, bypassing authorization checks. This means a logged-in user could potentially access or modify resources belonging to other users or perform actions they should not be permitted to perform. The vulnerability is remotely exploitable and public exploits are available.
- CVE-2026-10269MEDIUM 6.3
A vulnerability in decolua 9router allows an authenticated user to bypass authorization controls by manipulating the Host HTTP header. The flaw exists in the authentication logic of the dashboard guard component and can be exploited remotely by someone with valid login credentials. Affected versions up to 0.4.0 should be updated immediately to 0.4.1.
- CVE-2026-10693MEDIUM 6.3
SourceCodester Online Boat Reservation System version 1.0 contains a flaw in its administrative endpoints that fails to properly verify user permissions. An authenticated attacker can exploit this improper authorization to access or modify administrative functions they shouldn't have access to. The vulnerability requires an existing user account but can be exploited over the network without user interaction. The flaw affects multiple administrative endpoints, and exploit details have been publicly disclosed.
- CVE-2026-10876MEDIUM 6.3
SourceCodester Ship Ferry Ticket Reservation System version 1.0 contains an authorization bypass vulnerability affecting its admin panel. An authenticated user can manipulate the 'page' parameter in requests to /admin/ to access functions they should not be permitted to use. This vulnerability requires valid login credentials to exploit, but once authenticated, an attacker can view, modify, or delete unauthorized data. The vulnerability has been publicly disclosed with working exploits available, increasing active risk.
- CVE-2026-11336MEDIUM 6.3
A flaw in the College Management System allows authenticated users to bypass authorization controls and gain unauthorized access to sensitive administrative functions. An attacker with valid login credentials can manipulate a parameter called UserAuthData in the admin dashboard to perform actions they shouldn't be allowed to perform, potentially viewing, modifying, or deleting data. Because this vulnerability requires prior authentication and the exploit details are now public, it poses a meaningful security risk to organizations running this software.
- CVE-2026-11438MEDIUM 6.3
A security flaw in OneDev versions up to 15.0.5 allows authenticated users to manipulate project forking parameters in a way that bypasses authorization controls. An attacker with valid credentials can supply a crafted project ID in the forking mechanism to gain unauthorized access or modify projects they should not have permission to touch. This is a remote vulnerability requiring only standard user login—no special network access or user interaction needed beyond the attack itself.
- CVE-2026-11439MEDIUM 6.3
A vulnerability in OneDev up to version 15.0.5 allows authenticated users to manipulate parent project assignments in a way that bypasses authorization checks. An attacker with valid credentials can exploit the project.parentId parameter in the /projects/ endpoint to gain unauthorized access or make unauthorized changes to project hierarchies. This is a remote, network-accessible flaw that requires an existing user account to exploit.
- CVE-2026-11440MEDIUM 6.3
A vulnerability in OneDev versions up to 15.0.5 allows authenticated users to bypass authorization controls when modifying project default branch settings through the REST API. An attacker with login credentials can manipulate the `project.defaultBranch` parameter to gain unauthorized access or make changes they shouldn't be permitted to make. The vulnerability requires valid authentication to exploit but poses a moderate risk due to the potential for privilege escalation or unauthorized repository configuration changes.
- CVE-2026-11441MEDIUM 6.3
A flaw exists in theonedev onedev versions up to 15.0.5 that allows authenticated users to bypass authorization checks when accessing pull request issues. An attacker with valid credentials can manipulate how the system validates whether they have permission to view or modify specific issues, potentially gaining unauthorized access to sensitive project data. The vulnerability is straightforward to exploit once an attacker has credentials, and it requires only network access to the affected instance.
- CVE-2026-11461MEDIUM 6.3
NousResearch's hermes-agent contains a flaw that allows an authenticated user to bypass authorization checks by manipulating the 'Title' argument in the resume endpoint. An attacker with valid login credentials can access or modify information they shouldn't have permission to reach. The vulnerability affects versions up to 0.12.0, is remotely exploitable, and exploit details have been publicly disclosed.
- CVE-2026-11476MEDIUM 6.3
Kushan2k's student-management-system contains a flaw in its admin profile update endpoint that allows authenticated users to escalate their privileges by manipulating the 'isadmin' parameter. An attacker with legitimate credentials can modify this parameter to grant themselves administrative access without proper authorization checks. The vulnerability has already been disclosed publicly, and remote exploitation requires only network access and valid login credentials.
- CVE-2026-11519MEDIUM 6.3
SourceCodester Inventory System version 1.0 contains a privilege escalation vulnerability in its user account creation mechanism. An authenticated attacker can manipulate the ROLE parameter during account creation to bypass authorization controls and gain elevated privileges. The vulnerability requires valid login credentials but can be exploited remotely without user interaction. Public exploits are available, increasing the likelihood of active exploitation.
- CVE-2026-11521MEDIUM 6.3
A security vulnerability exists in the Transaction Endpoint of the Mohammed-eid35 bank-management-system-springboot project that allows authenticated users to perform actions they shouldn't be authorized for. The flaw lies in the TransactionController component and enables an attacker with valid login credentials to manipulate transaction data beyond their permitted scope. Because this is a publicly disclosed vulnerability affecting a banking system component, prompt remediation is important even though exploitation requires existing user access.
- CVE-2026-11619MEDIUM 6.3
A flaw exists in Dolibarr ERP CRM versions up to 23.0.2 within the Legacy Filemanager component. An authenticated attacker can exploit improper authorization controls in a configuration file to gain unauthorized access to functionality they should not have. The vulnerability allows remote exploitation and does not require user interaction. Public exploit code is available, increasing practical attack risk. The issue is resolved by upgrading to version 23.0.3 or later.
- CVE-2026-10218MEDIUM 5.4
A security flaw exists in nextlevelbuilder GoClaw versions up to 3.11.3 that allows authenticated users to perform actions they shouldn't be authorized to perform. The vulnerability resides in the authentication logic of the application and can be exploited remotely by someone with valid login credentials. Because the flaw has been publicly disclosed, there's elevated risk that attackers may attempt to exploit it.
- CVE-2026-10284MEDIUM 5.4
A security flaw in DevaslanPHP project-management versions up to 2.0.0-beta1 allows authenticated users to bypass authorization controls when editing or deleting comments in ticket management workflows. An attacker with login credentials can manipulate comment-related functions to perform actions they shouldn't be authorized to perform, such as deleting or modifying comments belonging to other users. The issue resides in the Livewire handler component and can be exploited remotely without requiring additional user interaction.
- CVE-2026-10285MEDIUM 5.4
DevaslanPHP project-management versions up to 2.0.0-beta1 contain an authorization flaw in the ticket handler component. An authenticated user can manipulate ticket records in ways they should not be permitted to perform, potentially modifying or deleting ticket data without proper access controls. The vulnerability requires an existing login but can be exploited remotely over the network.
- CVE-2026-11533MEDIUM 5.4
A vulnerability in the imvks786 student_management_system allows an authenticated user to bypass authorization controls on the student deletion function. By manipulating a parameter called 'del' in the /see.php endpoint, an attacker with login credentials can perform unauthorized deletions of student records. The vulnerability requires valid authentication but does not need special privileges, meaning any logged-in user—including those with limited access—could exploit it. Public disclosure has occurred, increasing the likelihood of active exploitation.
- CVE-2026-45620MEDIUM 5.3
CVE-2026-45620 is a user enumeration vulnerability in WWBN AVideo version 29.0 and earlier. The `objects/mention.json.php` endpoint lacks proper authentication controls and allows attackers to discover valid usernames on the platform without logging in. An attacker can craft requests to the endpoint and enumerate users by checking responses, potentially gathering intelligence for follow-up attacks like credential stuffing or targeted social engineering.
- CVE-2026-11500MEDIUM 5.0
Weaviate versions up to 1.37.7 contain an authorization bypass vulnerability in the static API key authentication handler. An authenticated attacker can manipulate the StaticApiKey parameter to bypass access controls and gain unauthorized access to protected resources. The vulnerability requires a valid user account and significant technical knowledge to exploit, but public exploit code exists. Upgrading to version 1.38.0-rc.0 resolves the issue.
- CVE-2026-47673MEDIUM 4.8
Hono, a JavaScript Web application framework, contains a flaw in its JWT authentication middleware that fails to enforce the Bearer scheme requirement. Prior to version 4.12.21, the jwt and jwk middlewares accept any two-part Authorization header value—regardless of whether it uses Bearer, Basic, Token, or any other scheme name—and proceed directly to JWT verification if the token is valid. This means an attacker could authenticate by presenting a valid JWT under an incorrect scheme (like Basic auth) and gain the same access as a properly formatted Bearer token request. The vulnerability is fixed in version 4.12.21.
- CVE-2026-10070MEDIUM 4.7
A flaw in macrozheng mall versions up to 1.0.3 allows an authenticated administrator with high privileges to bypass authorization controls on the super admin password update endpoint. An attacker with admin credentials could manipulate requests to the /admin/update/ path and gain unauthorized access to sensitive administrative functions. The vulnerability requires valid admin-level authentication and cannot be exploited anonymously from the network.
- CVE-2026-10154MEDIUM 4.3
Dolibarr ERP CRM versions 23.0.0, 23.0.1, and 23.0.2 contain an authorization bypass vulnerability in the user messaging module. An authenticated attacker can manipulate the ID parameter in htdocs/user/messaging.php to access or view information they should not have permission to see. The vulnerability requires valid login credentials but allows a logged-in user to circumvent access controls. Upgrading to version 23.0.3 resolves the issue.
- CVE-2026-10215MEDIUM 4.3
A flaw in Dolibarr ERP CRM's Leave Request REST API fails to properly check whether users have permission to access specific leave request objects. An authenticated attacker can remotely exploit this to view leave data they should not be able to see. The vulnerability affects versions up to 23.0.1, and Dolibarr has released version 23.0.2 as a fix. Because the exploit has been publicly disclosed, this poses an active risk despite its moderate CVSS score.
- CVE-2026-10282MEDIUM 4.3
Bottelet DaybydayCRM versions up to 2.2.1 contain an authorization flaw in the Documents controller that allows authenticated users to access files they shouldn't be able to view. An attacker with valid login credentials can exploit this remotely to read sensitive documents beyond their intended access scope. The vulnerability is rated MEDIUM severity and requires patching.
- CVE-2026-10294MEDIUM 4.3
PackageKit, a system library for package management on Linux, contains an authorization bypass vulnerability in versions up to 1.3.5. An authenticated attacker can manipulate the frontend-socket parameter in the API to gain unauthorized access to sensitive information. The vulnerability requires an existing user account to exploit but does not require user interaction. While the attack surface is somewhat limited by authentication requirements, the unauthorized information disclosure poses a real security concern for systems relying on PackageKit.
- CVE-2026-41115MEDIUM 4.3
Apache Kafka contains an authorization mismatch in its consumer group metadata API. The CONSUMER_GROUP_DESCRIBE operation checks for DESCRIBE permission on groups, but Kafka's documentation and the relevant design specification (KIP-848) incorrectly state it should check for READ permission. This inconsistency between code behavior and documentation can lead to misconfigured access controls—either granting unintended READ access to users who only have DESCRIBE permissions, or blocking legitimate access for users who rely on documentation-based ACL configurations. The vulnerability is not a code flaw but a documentation gap that can cause real-world security postures to diverge from intent.
- CVE-2026-46605MEDIUM 4.3
Apache ActiveMQ has an authorization flaw that allows authenticated users to delete message queues and topics they shouldn't be able to modify. An attacker with valid credentials to your messaging system could disrupt operations by removing critical destinations, even if permission controls suggest they shouldn't have that ability. This affects ActiveMQ versions before 5.19.7 and 6.0.0 through 6.2.5.
- CVE-2026-48810MEDIUM 4.3
FreeScout, a free help desk platform built on Laravel, contains an authorization flaw in version 1.8.220 and earlier. A user with conversation editing permissions who authored a message in one mailbox can edit that message's content even after an administrator removes them from that mailbox. The vulnerability exploits a gap in access controls: the system verifies the user created the message and has the global edit permission, but fails to confirm the user still belongs to the mailbox where the conversation lives. This allows former mailbox members to alter thread history and potentially mislead team members or customers.
- CVE-2026-40963LOW 3.1
Apache Airflow's UI structure_data endpoint was leaking metadata about linked workflows (DAGs) to users who shouldn't see them. An authenticated user with permission to view one workflow could discover the names and dependency relationships of other workflows they weren't authorized to access. This is a read-only information disclosure—no data modification or system disruption occurs—but it can undermine team isolation in multi-tenant Airflow deployments where workflow topology is considered sensitive.
- CVE-2026-47713LOW 2.0
AnythingLLM versions before 1.13.0 contain a token persistence flaw that can leak sensitive data when administrators migrate from single-user to multi-user mode. A mobile device token issued in single-user mode may remain valid after the migration, allowing it to bypass user-scoping controls and access workspaces and chat content belonging to other users. The vulnerability requires an attacker to have had a legitimate mobile device token before the migration, then exploit it post-migration in the multi-user environment.