By weakness (CWE)
CWE-862: related vulnerabilities
CVEs classified under CWE-862. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
359 published vulnerabilities · page 2 of 4
- CVE-2026-59708HIGH 7.5
Ghostfolio's public portfolio sharing feature contains an authentication bypass vulnerability that allows anyone with a private access ID to retrieve complete portfolio details without logging in. The flaw lies in insufficient validation of user permissions when accessing the /api/v1/public/:accessId/portfolio endpoint. An attacker who obtains a private access ID—whether through social engineering, data leaks, or enumeration—can view sensitive investment information including specific holdings, quantities purchased, entry prices, and performance metrics that the portfolio owner intended to keep private. The vulnerability requires network access but no special privileges or user interaction, making it straightforward to exploit.
- CVE-2026-9178HIGH 7.5
The WP Forms Connector plugin for WordPress has a flaw that allows attackers to steal sensitive user information without needing valid credentials. The plugin exposes a REST API endpoint that is supposed to require authentication, but its password check is broken—it accepts any password as long as you know an admin username (typically 'admin'). This means an attacker can retrieve password hashes, email addresses, and other private data for any user on the site by making a simple web request.
- CVE-2025-69189HIGH 7.3
EMV JobBank versions up to 1.2.3 contain a missing authorization flaw that allows unauthenticated attackers to exploit improperly configured access controls. An attacker can access sensitive functionality without providing valid credentials, potentially reading, modifying, or disrupting data and services depending on what the unprotected endpoints expose.
- CVE-2026-42675HIGH 7.3
Themefic Hydra Booking versions up to 1.1.41 contain a missing authorization flaw that allows attackers to bypass access controls and perform unauthorized actions. An attacker without authentication can exploit incorrectly configured security levels to access or modify booking data and functionality that should be restricted. This is a network-based vulnerability requiring no user interaction or special privileges.
- CVE-2026-0272HIGH 7.2
CVE-2026-0272 is a privilege escalation flaw in Palo Alto Networks PAN-OS that lets an authenticated administrator with CLI access run commands as root. While the vulnerability requires pre-existing admin credentials and CLI access, the impact is severe: a malicious or compromised admin account could gain unrestricted control of the firewall. The risk is substantially reduced when CLI access is tightly limited to a small trusted group and the management interface is restricted to known internal IP ranges.
- CVE-2026-1667HIGH 7.2
The Squirrly SEO WordPress plugin, in versions up to 14.0.0, exposes an API token that attackers can exploit without any authentication. This allows them to create arbitrary posts on affected WordPress sites. If the Advanced Custom Fields plugin is also installed, attackers can inject malicious scripts that run whenever visitors view the affected pages, potentially stealing credentials or spreading malware.
- CVE-2026-44914HIGH 7.2
Apache NiFi versions 1.12.0 through 2.9.0 contain a flaw where the system fails to properly verify user permissions when someone tries to replace Process Groups that contain restricted components. Restricted components are those requiring elevated privileges, but the framework skipped this authorization check during replacement operations. This means a user with basic write access could circumvent intended security controls and deploy restricted components without proper authorization. The vulnerability is effectively a privilege escalation through authorization bypass in the Process Group replacement workflow.
- CVE-2026-53816HIGH 7.2
OpenClaw contains a flaw that allows malicious or compromised paired nodes to forge execution lifecycle events without proper authorization checks. In a paired-node architecture, each node is normally restricted in what actions it can perform. This vulnerability enables an attacker controlling a paired node to send specially crafted messages to the gateway that trick sessions into exposing capabilities that should be blocked at the reduced node level. The issue stems from insufficient validation of event provenance—essentially, the system does not adequately verify that lifecycle events truly originated from an authorized source before acting on them.
- CVE-2026-8848HIGH 7.2
The Popup Maker plugin for WordPress—a tool used to create popup forms for lead capture and conversions—contains a flaw that allows editors and higher-privileged users to bypass normal approval processes and force installation of malicious plugins. An attacker with editor-level access can install any plugin they choose from a URL they control, ultimately gaining full control over the WordPress site. This attack only works if the site has a valid Popup Maker Pro license but hasn't yet installed the Pro version of the plugin.
- CVE-2026-31942HIGH 7.1
LibreChat versions up to 0.7.6 contain a critical flaw in how API keys are managed. Any authenticated user can manipulate API key settings for other users by injecting parameters into requests, allowing them to replace legitimate API keys (from providers like OpenAI, Anthropic, or Azure) with their own or invalid ones. This means an attacker could intercept conversations through attacker-controlled API endpoints or disable a victim's service entirely.
- CVE-2026-44751HIGH 7.1
An ABAP application server fails to verify user permissions when processing report generation commands. An authenticated attacker can bypass authorization checks to execute reports that overwrite data belonging to other users, effectively gaining unauthorized access to modify information they should not be able to touch. This is a privilege escalation vulnerability accessible to anyone with valid login credentials.
- CVE-2026-47120HIGH 7.1
Nezha Monitoring, a self-hosted monitoring tool, contains an authorization bypass flaw affecting versions 1.4.0 through 2.0.7. A user with RoleMember privileges can trigger cron tasks (scheduled automation jobs) owned by other users without proper permission checks. While the attacker cannot see the tasks' contents or modify them, they can force execution, potentially disrupting monitoring workflows or triggering unintended automated actions. The vulnerability requires authenticated access and has been fixed in version 2.0.8.
- CVE-2026-48119HIGH 7.1
Nezha Monitoring, a self-hosted server and website monitoring tool, contains a vulnerability that allows authenticated agents to falsify monitoring results for services owned by other users. An attacker with valid agent credentials can forge service health data, creating false alerts or hiding actual service problems. The vulnerability affects versions 0.20.0 through 2.0.11 and is resolved in version 2.0.12.
- CVE-2026-5230HIGH 7.1
CVE-2026-5230 is a high-severity access control flaw in MIA Technology Inc.'s Pizzy Library that allows authenticated users to bypass authorization checks and access data or functionality they shouldn't have permission to reach. The vulnerability stems from incorrectly configured security levels that fail to properly validate user privileges. Versions 1.0.0.26250 through 1.3.8.26250 are affected; upgrading to 1.3.9.26250 or later resolves the issue.
- CVE-2026-54012HIGH 7.1
Open WebUI, a self-hosted AI platform, contains a flaw in how it manages file access permissions tied to AI models. Before version 0.9.6, a user who creates or imports a model can attach references to files belonging to other users without any verification. This allows the malicious model owner to read or delete those private files by manipulating how the system validates file access. The vulnerability requires an authenticated attacker but poses a direct threat to data confidentiality and integrity within shared Open WebUI deployments.
- CVE-2026-56280HIGH 7.1
Cap-go versions before 12.128.2 contain a privilege escalation flaw in their build log streaming feature. An attacker with a read-only API key—which should only permit viewing logs—can actually cancel active native builds by connecting to the log stream and then disconnecting. This happens because the server uses its own privileged credentials to clean up when clients disconnect, rather than checking whether the client itself has permission to cancel builds. The vulnerability allows repeated disruption of build pipelines and CI/CD workflows without requiring elevated API credentials.
- CVE-2026-57332HIGH 7.1
A vulnerability in the Wallet System for WooCommerce plugin allows authenticated subscribers to bypass access controls and perform actions they shouldn't be authorized to perform. The issue affects versions 2.7.6 and earlier. An attacker with a subscriber account—the lowest privilege level in WordPress—can escalate their capabilities to modify or delete wallet data, affecting the integrity of transaction records and potentially causing financial discrepancies for merchants and customers.
- CVE-2026-57520HIGH 7.1
Bitwarden Server versions before 2026.5.0 contain a privilege escalation flaw that allows authenticated users with limited ManageUsers permissions to remove administrator accounts from an organization. An attacker with a Custom user role could exploit a gap in the bulk user-removal endpoint to delete Admin accounts that would normally be protected, potentially compromising organizational access controls and administrative oversight.
- CVE-2026-59704HIGH 7.1
Cap's video AI metadata endpoint allows authenticated users to access private AI-generated content belonging to other users without permission checks. An attacker with valid credentials can request arbitrary video IDs and retrieve sensitive metadata like AI-generated titles, summaries, and chapters. Worse, the endpoint can be abused to trigger new AI generation tasks that drain the video owner's credit balance without their knowledge or consent.
- CVE-2026-10609MEDIUM 6.8
OpenShift Cluster Logging Operator contains a flaw in how it handles ServiceAccount credentials. When an operator creates a log forwarder, it automatically generates and sends ServiceAccount tokens to external destinations without first checking whether the person setting up the forwarder should have access to those credentials. This means a delegated editor—someone with limited permissions to modify cluster configurations—could trick the system into exposing sensitive authentication tokens, then use those tokens to gain higher privileges than they should have.
- CVE-2026-44754MEDIUM 6.6
CVE-2026-44754 is a missing access control issue in SAP's Operational Data Provisioning (ODP) Remote Function Call module. The RFC interface is not properly verifying which applications are permitted to use it, allowing unapproved customer or third-party applications to call functions they shouldn't have access to. This creates an uncontrolled data disclosure risk but does not compromise data integrity or significantly impact system availability. The vulnerability requires an attacker to already have high-level privileged access to the environment, which limits immediate exploitability in most organizations.
- CVE-2026-53818MEDIUM 6.6
OpenClaw versions before 2026.4.24 have a security flaw in their MCP loopback feature that lets unauthorized users bypass owner-level restrictions. An attacker with local access can invoke privileged tools that should only be available to the system owner, potentially leading to unauthorized actions within OpenClaw's environment.
- CVE-2026-53820MEDIUM 6.6
OpenClaw versions before 2026.5.12 contain a security flaw that allows authorized users to bypass restrictions on what commands they can execute. The vulnerability exists in the bundled MCP (likely a module or component interface) loopback session-spawn mechanism. An authenticated attacker can exploit this to gain access to command execution capabilities that should have been restricted, potentially allowing them to perform actions beyond their intended permissions.
- CVE-2024-37210MEDIUM 6.5
CVE-2024-37210 is a missing authorization flaw in ali2woo AliNext that allows authenticated users to access resources or perform actions they shouldn't be permitted to reach due to improperly configured access controls. An attacker with valid login credentials can exploit weak authorization checks to view sensitive information, though they cannot modify data or disrupt service availability. All versions through 3.3.5 are affected.
- CVE-2025-52766MEDIUM 6.5
CVE-2025-52766 is a missing authorization flaw in Printeers Print & Ship that allows authenticated users to perform actions they shouldn't have permission to do. An attacker with valid login credentials can exploit improperly configured access controls to modify data or settings—for instance, altering print job configurations, shipping labels, or account information belonging to other users or tenants. The vulnerability requires an authenticated user; it cannot be exploited by unauthenticated attackers. The impact is elevation of privilege within the application, not confidentiality compromise or service disruption.
- CVE-2025-64215MEDIUM 6.5
StylemixThemes MasterStudy LMS Pro contains a missing authorization vulnerability that allows unauthenticated attackers to access functionality that should be restricted by access control lists (ACLs). An attacker can exploit this flaw to perform unauthorized actions affecting the integrity and availability of the learning management system without requiring authentication or user interaction.
- CVE-2026-11852MEDIUM 6.5
Debusine, a tool used to build and maintain Debian-based Linux distributions, contains a permission-checking flaw in its artifact management system. When users or services create or delete relationships between artifacts (the packaged components that make up a distribution), the system fails to verify whether the requester has authorization to perform those actions. An attacker who can see an artifact can manipulate its relationships without proper permission checks, potentially corrupting the integrity of a distribution build or exposing sensitive artifacts to unauthorized access.
- CVE-2026-12105MEDIUM 6.5
Devolutions Server contains an access control weakness that allows authenticated users to view attachments they shouldn't have permission to access. The issue occurs when a folder is duplicated—the inherited permissions aren't properly restricted, giving users unintended access to sensitive files. An attacker would need valid login credentials to exploit this, but once authenticated, they could escalate their view into restricted attachment areas without additional authorization.
- CVE-2026-12119MEDIUM 6.5
The Simple File List WordPress plugin contains a flaw that allows authenticated users with basic contributor privileges to perform unauthorized file operations on a server. An attacker can exploit this by creating a draft post, extracting a security token from its preview, and then using that token to delete files, move files, create folders, or download files—bypassing the plugin's intended access controls. This affects all versions up to 6.3.7.
- CVE-2026-12428MEDIUM 6.5
The Blocks for ACF Fields plugin for WordPress has a flaw that lets authenticated users view sensitive ACF field data they shouldn't be able to see. Anyone with Author-level access or higher can read field values from private posts, drafts, or other posts belonging to different users by making requests to a specific REST API endpoint. The plugin only checks if a user can publish posts (a very broad permission) rather than verifying they actually own or have permission to view the specific content they're trying to access.
- CVE-2026-14156MEDIUM 6.5
A flaw in Google Chrome's StorageAccessAPI allowed attackers who had already compromised the browser's rendering engine to bypass the same-origin policy—a core security boundary that prevents malicious websites from accessing data belonging to other sites. The attacker would need to trick a user into visiting a specially crafted webpage while the renderer process was already compromised. This vulnerability affects Chrome versions before 150.0.7871.47.
- CVE-2026-1869MEDIUM 6.5
A critical vulnerability in the popular User Registration & Membership WordPress plugin allows attackers to bypass payment processing and activate premium memberships without paying. The flaw exists in the payment confirmation function, which fails to validate user input properly. Any visitor to a site running the vulnerable plugin can exploit this to gain access to paid content and features, potentially causing revenue loss and unauthorized access to restricted materials.
- CVE-2026-2381MEDIUM 6.5
The WooCommerce Stripe Payment Gateway plugin contains a flaw that allows attackers to sabotage pending orders without authentication. By exploiting a missing verification step, attackers can force orders into a failed state using a fake payment method. This attack works because the plugin only checks a security token that is publicly visible on WooCommerce checkout pages, and does not confirm the attacker actually owns or has permission to modify the order being targeted. Attackers can enumerate sequential order IDs to identify and attack multiple orders.
- CVE-2026-34050MEDIUM 6.5
Coolify is a popular open-source server and application management platform. A flaw in its Settings/Updates component allows any authenticated user—not just administrators—to view and potentially alter automatic update settings or force update checks. This access control gap was present before version 4.0.0-beta.471. While an attacker would need valid login credentials, the lack of role-based authorization on this sensitive functionality creates meaningful risk in multi-user environments.
- CVE-2026-3462MEDIUM 6.5
The Frisbii Pay plugin for WordPress has a critical authorization flaw that allows low-privilege users (Subscriber level and above) to upload malicious CSV files and alter sensitive payment and order data. An attacker with basic authenticated access can overwrite WooCommerce payment tokens and customer order information without needing administrative rights, potentially compromising transaction integrity and customer payment records.
- CVE-2026-40773MEDIUM 6.5
A broken access control vulnerability exists in rtMedia for WordPress, BuddyPress, and bbPress versions 4.7.9 and earlier. The flaw allows authenticated subscribers to modify or access content they should not have permission to change, such as other users' media or metadata. While an attacker needs a valid account to exploit this, the vulnerability poses a significant risk to multi-user WordPress installations where subscriber-level access is commonly granted.
- CVE-2026-40809MEDIUM 6.5
Rara Themes' Metro Magazine contains a missing authorization flaw that allows unauthenticated attackers to modify content and disrupt service availability. The vulnerability stems from incorrectly configured access controls that fail to properly validate user permissions before processing sensitive operations. Attackers can exploit this over the network without requiring any special setup or user interaction.
- CVE-2026-42671MEDIUM 6.5
Paolo GeoDirectory versions up to 2.8.157 contain a missing authorization flaw that allows attackers to bypass access controls. Without needing credentials or user interaction, an attacker on the network can exploit misconfigured security levels to gain unauthorized access to sensitive operations, potentially modifying data or causing service disruption.
- CVE-2026-44734MEDIUM 6.5
OpenProject versions before 17.3.2 and 17.4.0 contain a flaw that allows any logged-in user to rename or modify the filters and grouping settings of public cost reports, even if they don't own them. An attacker who learns the numeric ID of a public cost report—either by discovery or guessing—can alter its configuration without the actual owner being notified. This undermines report integrity and can lead to data confusion or operational disruption. The vendor has patched this in versions 17.3.2 and 17.4.0.
- CVE-2026-44884MEDIUM 6.5
Portainer Community Edition versions 2.33.0 through 2.33.7 and 2.39.0 contain a flaw that lets any logged-in user view template files they shouldn't have access to. By trying different ID numbers, an attacker can enumerate and read custom template files that may hold sensitive credentials or connection strings—data that administrators likely assume only authorized users can see. The vulnerability has been patched in versions 2.33.8 and 2.39.1.
- CVE-2026-45267MEDIUM 6.5
Nextcloud versions before 5.2.6 contain a security flaw where the application fails to properly check user permissions when handling form submissions. This allows authenticated users to view form submission data belonging to other users—data they should not have access to. An attacker with valid Nextcloud credentials can exploit this to read sensitive information submitted by colleagues or other organization members through forms. The vulnerability requires an existing user account but does not need special privileges or user interaction to trigger.
- CVE-2026-46413MEDIUM 6.5
Discourse, a widely-used open-source discussion platform, contains a vulnerability that allows regular (non-admin) users to upload files to sensitive backup storage areas that should be restricted to administrators only. An authenticated user can exploit S3 multipart upload functionality to bypass access controls and write files into the admin backup store. This is a privilege-escalation issue affecting data integrity rather than confidentiality; the vulnerability requires an existing user account but does not require special permissions to trigger.
- CVE-2026-47742MEDIUM 6.5
Shopper is a headless e-commerce admin platform that manages product catalogs and inventory. A flaw in versions prior to 2.8.0 allowed any logged-in panel user to modify product information—including prices, stock levels, SEO details, shipping dimensions, and media attachments—even if they lacked explicit permission to edit products. The vulnerability stems from missing authorization checks on specific sub-form components and the ability for attackers to manipulate product IDs client-side to target arbitrary products. An authenticated attacker with minimal privileges could cause significant data integrity issues without detection.
- CVE-2026-47745MEDIUM 6.5
Shopper, a headless e-commerce admin panel used to manage online stores, contains a permission-checking flaw in versions before 2.8.0. Admin users with low-level access can manipulate critical payment and fulfillment settings—such as disabling all payment methods, changing the default currency, or removing shipping carriers—even though they shouldn't have permission to do so. Any employee or contractor with admin panel access, regardless of their intended role, can trigger a complete checkout blockade or corrupt pricing data. The vendor has resolved this in version 2.8.0.
- CVE-2026-48492MEDIUM 6.5
Snipe-IT versions before 8.6.1 have an authorization bypass in the user list API endpoint. Any employee logged into Snipe-IT can retrieve a complete list of all user accounts in the system without needing special permissions or an API token. This leaks usernames, display names, employee numbers, and user IDs—sensitive directory information that could be useful for social engineering, phishing, or reconnaissance. The vulnerability requires an active user session to exploit, but does not require admin rights or knowledge of credentials beyond what any valid employee already has.
- CVE-2026-48500MEDIUM 6.5
Filament, a Laravel development framework, has a vulnerability in how it handles file uploads on authentication-required components. The framework automatically enables file upload capability on all schema-based forms, including pages that shouldn't allow uploads—like the login form. This means an attacker without credentials could upload files to your server's temporary storage without any restrictions, potentially filling up disk space or running up storage costs. The issue affects versions 3.0.0 through 3.3.51, 4.0.0 through 4.11.4, and 5.0.0 through 5.6.4.
- CVE-2026-4881MEDIUM 6.5
Octopus Server contains a missing permission check in one of its API endpoints. Any authenticated user—even with minimal privileges—can exploit this flaw to make server-level changes, such as modifying configuration or access controls. The vulnerability is deceptive: the API returns an error message to the caller, but the requested changes are applied anyway. This allows a low-privileged insider or compromised account to escalate their impact significantly.
- CVE-2026-48941MEDIUM 6.5
CVE-2026-48941 is a medium-severity vulnerability in the K2 Joomla component that allows an attacker to delete gallery folders without authentication. The flaw exists in the `item.checkin` task, which accepts a user-supplied folder path parameter and passes it unsafely to a file deletion function. An attacker can craft a request specifying any gallery folder path to trigger unauthorized deletion of media files, potentially disrupting site content or causing data loss.
- CVE-2026-49205MEDIUM 6.5
phpMyFAQ versions before 4.1.4 contain an authorization bypass in four API endpoints that allow authenticated users to perform privileged actions (create and modify FAQ content) without proper permission checks. The vulnerability stems from reliance on a shared API key validation rather than checking individual user permissions. A user with valid API credentials but no administrative privileges can create categories, FAQs, questions, and modify FAQs—actions that should be restricted to authorized administrators.
- CVE-2026-49385MEDIUM 6.5
JetBrains YouTrack contains an access control flaw that allows standard users to modify service accounts—privileged system identities that handle automated tasks and integrations. This is a privilege escalation risk because service accounts typically have elevated permissions, and unauthorized modification could allow an attacker to hijack critical workflows or lateral-move within the organization. The vulnerability affects YouTrack versions prior to 2026.1.13570.
- CVE-2026-49956MEDIUM 6.5
Hermes WebUI versions before 0.51.269 have a profile isolation flaw that lets logged-in users view other users' conversations and session data. An attacker with valid credentials can query the sessions search endpoint in a way that bypasses profile restrictions, exposing session titles and message transcripts they shouldn't be able to access. The vulnerability requires authentication but doesn't need user interaction to exploit.
- CVE-2026-52866MEDIUM 6.5
A nearby attacker can flood a device's Bluetooth Low Energy (BLE) connection slot, locking out legitimate users and applications from connecting. The attacker doesn't need credentials or user interaction—they simply need to be within wireless range. This is a denial-of-service attack that affects availability rather than confidentiality or integrity.
- CVE-2026-53815MEDIUM 6.5
OpenClaw versions before 2026.5.19 allow authenticated users with limited privileges to read messages from channels they should not have access to. The vulnerability stems from missing validation checks that would normally restrict users to an allowlist of permitted channels. An attacker with any login credentials could exploit this to view sensitive communications intended only for specific teams or roles.
- CVE-2026-53844MEDIUM 6.5
OpenClaw versions before 2026.4.29 contain a flaw that allows authenticated users to bypass session visibility controls when searching shared memory. An attacker with valid credentials can craft searches to retrieve memory entries that should be restricted from their session, exposing data they should not have access to. This is a data exposure risk that requires valid authentication to exploit, but once inside the system, attackers can circumvent intended data compartmentalization.
- CVE-2026-54019MEDIUM 6.5
Open WebUI, a self-hosted AI platform designed for offline operation, contains a vulnerability in how it controls access to data collections when running in Milvus multitenancy mode. Even though version 0.9.6 added access controls at the collection level, an attacker with valid credentials can bypass these protections by exploiting how user-supplied collection names are processed. The vulnerability allows an authenticated user to access or manipulate collections they should not have permission to view, potentially exposing sensitive AI training data or model information. This is a partial fix for an earlier vulnerability (CVE-2026-44560) that was incompletely addressed.
- CVE-2026-54027MEDIUM 6.5
LibreChat, a multi-provider AI chat application, contains an authorization bypass in its image upload endpoint. Authenticated users can upload files into any agent's resource storage without permission checks, bypassing existing controls on the standard file upload route. An attacker with basic login credentials can inject malicious files into other users' agents, potentially compromising their AI tool execution environments.
- CVE-2026-56402MEDIUM 6.5
NanoClaw versions before 2.1.17 contain a privilege escalation flaw that allows authenticated users to approve or reject sensitive actions—such as package installations—without having the authorization role to do so. An attacker who has legitimate access to the system can exploit a missing validation check in the approval response handler to perform privileged operations they shouldn't be able to execute, potentially installing malicious packages or disrupting system integrity.
- CVE-2026-56695MEDIUM 6.5
OpenHarness ohmo gateway contains a configuration flaw where two slash commands—/resume and /summary—treat all authenticated users as capable of invoking remote operations by default. An attacker with legitimate access to a shared gateway channel can exploit this to discover and retrieve session snapshots belonging to other users simply by guessing or enumerating snapshot IDs. These snapshots may contain sensitive information such as system prompts, stored credentials, tool execution results, and internal file paths.
- CVE-2026-57669MEDIUM 6.5
A broken access control flaw exists in Advanced Contact Form 7 DB versions up to and including 2.0.9. An authenticated subscriber with low privileges can access or read sensitive contact form data they should not be permitted to view. The vulnerability requires an existing user account but no special interaction, making it a practical concern for WordPress sites using this plugin where user roles and data segregation matter.
- CVE-2026-57949MEDIUM 6.5
RuoYi-Vue-Pro versions up to 2026.05 contain a flaw in the CRM module that allows logged-in users to view follow-up records belonging to other users. The vulnerability exists in the GET /admin-api/crm/follow-up-record/get endpoint, which fails to verify that a user should have access to a specific record before returning it. An attacker can guess or iterate through record IDs to retrieve sensitive information including notes, attachments, scheduling data, and linked business entities. This is an insecure direct object reference (IDOR) vulnerability that requires valid credentials but places no restrictions on which records an authenticated user can read.
- CVE-2026-58167MEDIUM 6.5
Nightingale (n9e), an open-source observability platform, contains a credential disclosure vulnerability in its datasource management API. Any user with standard (low-privilege) access can retrieve the complete configuration of all connected data sources—including plaintext database passwords, API tokens, and encryption keys—through a single API endpoint. This happens because the endpoint lacks proper permission checks that are present on other similar operations, and the response is not filtered to remove sensitive fields. An attacker with legitimate low-privilege credentials can use disclosed secrets to gain unauthorized access to backend databases, monitoring systems, and other connected infrastructure.
- CVE-2026-58176MEDIUM 6.5
RuoYi-Vue-Plus is a workflow and task management platform. Versions through 5.6.2 contain a critical authorization gap: the workflow task management system fails to validate whether users should be allowed to perform sensitive actions. This means any employee with basic system access—regardless of their job role—can reassign approval tasks to themselves or others, see all pending approvals organization-wide, and manipulate the workflow process. This breaks the fundamental control that prevents one person from both initiating and approving the same transaction.
- CVE-2026-58448MEDIUM 6.5
yudao-cloud versions before 2026.06 have a broken access control flaw in their BPM (Business Process Management) module. Any authenticated user can view process instance records they shouldn't have access to by crafting requests with process IDs. An attacker with valid login credentials can read sensitive workflow data belonging to other users or organizations—including form submissions, approver names, comments, and process definitions—without needing ownership or administrative rights.
- CVE-2026-59262MEDIUM 6.5
AFFiNE, a collaborative workspace application, contains a flaw in its document history feature that allows workspace members to view the edit timeline of private documents they shouldn't have access to. An authenticated attacker can request the history of any document by its identifier, and the system will return detailed records including who edited the document, their email addresses, and when changes occurred—regardless of whether the attacker has permission to view the actual document. This is a permission-bypass issue affecting information disclosure.
- CVE-2026-59805MEDIUM 6.5
Gumroad has a vulnerability in how it controls access to seller features. An authenticated seller can trick the system into revoking or restoring customer access to products they don't own. This happens because the system doesn't properly verify that a seller is the legitimate owner before processing access changes. The flaw exists in versions before 2026.07.06.2 and could allow sellers to maliciously disrupt competitors' sales or restore access inappropriately.
- CVE-2026-59853MEDIUM 6.5
SiYuan is an open-source personal knowledge management application that helps users organize and search their notes and documents. A flaw in versions prior to 3.7.1 allows users with read-only 'publish mode' access to view private information they shouldn't be able to access—specifically, the internal IDs and file paths of unpublished documents, notebooks, and individual text blocks, as well as the search keywords other users have saved. This happens because one API endpoint doesn't properly filter what data it exposes, unlike the similar endpoints around it that do apply the correct restrictions.
- CVE-2026-61441MEDIUM 6.5
PraisonAI Platform versions before 0.1.9 contain an authorization bypass vulnerability in their issue dependency deletion feature. A workspace member can delete dependencies created by owners or admins by targeting the deletion request through a related issue they own, rather than the owner-controlled issue. The system validates permissions only against the issue being targeted in the request, not against both sides of the dependency relationship, enabling lower-privileged users to remove critical issue links that should be protected.
- CVE-2026-8996MEDIUM 6.5
The WP Time Capsule backup plugin contains a flaw that allows any authenticated WordPress user with subscriber-level permissions or higher to download the most recent decrypted SQL database backup file. This backup typically contains sensitive data like password hashes, user credentials, and configuration secrets. The vulnerability only manifests if a site administrator has previously decrypted a backup—otherwise, no file is available to exploit. An attacker with even basic user access can trigger this exposure without any additional action from site administrators.
- CVE-2026-9132MEDIUM 6.5
A security flaw in GitHub Enterprise Server allowed authenticated users to view source code from private repositories they shouldn't have access to. The vulnerability existed in the Copilot pull request description feature, which compared code across repositories without properly checking if the user had permission to see the target repository. An attacker needed only a valid account with read access to at least one repository on the instance to exploit this and extract sensitive code from restricted repositories.
- CVE-2026-39594MEDIUM 6.4
A broken access control flaw in Ultra Addons for WPForms allows authenticated users to perform actions they shouldn't be permitted to perform, potentially modifying content or disrupting service for other users. The vulnerability affects versions up to and including 1.0.11. While an attacker needs a valid login, the impact extends across the broader WordPress installation, making this a medium-severity issue that requires prompt attention from site administrators running the affected plugin.
- CVE-2026-45285MEDIUM 6.4
Nextcloud inadvertently creates hidden public links when users share folders or files with Teams that include external members (people invited via email without Nextcloud accounts). These links remain invisible in the sharing interface but are emailed to the external recipient and grant full permissions—read, write, delete, reshare, download. An attacker intercepting or receiving one of these links gains unfettered access to all shared data without authentication, and the folder owner cannot see or revoke the link through normal UI controls. Versions 32.0.0–32.0.8 and 33.0.0–33.0.2 are vulnerable; patches are available.
- CVE-2026-10815MEDIUM 6.3
A missing authorization vulnerability was discovered in the Hostel Management System PHP application, specifically in the Admin Dashboard Page's index.php file. An authenticated attacker can manipulate the ID parameter to bypass authorization checks, potentially gaining unauthorized access to sensitive administrative functions. The vulnerability requires valid login credentials but does not require user interaction once authenticated. Public exploit code is available, increasing the practical risk.
- CVE-2026-15332MEDIUM 6.3
A flaw in zhayujie CowAgent (versions up to 2.1.0) allows authenticated users to perform unauthorized actions through the Message Endpoint. The vulnerability exists in the channel/channel.py component and lacks proper authorization checks, meaning someone with basic login credentials could potentially access or modify data they shouldn't be able to. An exploit has already been published publicly, making active exploitation more likely.
- CVE-2026-52714MEDIUM 5.9
Squirrly SEO, a WordPress SEO plugin, contains a flaw that allows unauthenticated attackers to modify content or settings without proper authorization. An attacker does not need login credentials to perform certain privileged actions, bypassing the plugin's access controls. The vulnerability affects versions 12.4.16 and earlier. While the attack requires specific conditions to succeed (reflected in the CVSS score of 5.9), any unauthenticated modification capability represents a meaningful risk to site integrity.
- CVE-2026-57323MEDIUM 5.8
A vulnerability in Flash & HTML5 Video versions 2.11.0 and earlier allows unauthenticated attackers to access restricted resources without proper permission checks. The flaw stems from broken access control logic that fails to enforce authentication requirements, potentially exposing sensitive video content or configuration data to unauthorized parties over a network. Exploitation does not require user interaction or special privileges.
- CVE-2026-28573MEDIUM 5.5
CVE-2026-28573 is a medium-severity vulnerability in Android's manifest configuration that allows a local attacker with limited user privileges to repeatedly crash or disable Android system functionality without needing to interact with the device directly. The flaw stems from missing permission validation in the AndroidManifest.xml processing, making it trivial to exploit once an attacker gains basic system access.
- CVE-2026-28587MEDIUM 5.5
CVE-2026-28587 is a local information disclosure vulnerability in Android's MmsSmsProvider component that allows an authenticated attacker to retrieve sensitive information without additional privileges or user interaction. The vulnerability stems from a missing permission check in the MmsSmsProvider.java file, potentially exposing SMS and MMS data to unauthorized local access.
- CVE-2026-33802MEDIUM 5.5
A local authentication bypass in Juniper EX Series switches allows an already-logged-in user without special privileges to run a sensitive CLI command that crashes network traffic, effectively disabling the switch until it recovers on its own. The attacker must already have console or SSH access, but does not need administrative rights to cause the outage.
- CVE-2026-40722MEDIUM 5.5
Yoast SEO Premium contains a missing authorization flaw that allows authenticated administrators to perform actions they shouldn't be able to perform, potentially modifying content or causing service disruption. The vulnerability affects versions up to and including 26.6. While exploitation requires administrative-level access and doesn't compromise confidentiality, it does enable unauthorized modification of system state and availability.
- CVE-2026-44918MEDIUM 5.5
OpenStack Ironic, a service that manages bare metal computing resources, contains an authorization flaw that allows privileged users to create or modify compute nodes belonging to other projects without proper access controls. An attacker with administrative credentials in one project could gain visibility and control over infrastructure resources that should be isolated to separate projects or organizations, though they cannot read sensitive data or cause service outages directly.
- CVE-2026-53850MEDIUM 5.5
OpenClaw versions prior to 2026.4.25 contain a flaw in the focus command that bypasses authorization checks. An authenticated attacker can change focus state in ways the system administrator did not intend, potentially gaining unauthorized influence over gateway operations. The vulnerability requires valid credentials but does not require user interaction, making it a persistent risk in multi-tenant or shared-access deployments.
- CVE-2026-55628MEDIUM 5.5
ImageMagick's `-concatenate` operation fails to enforce security policies that restrict file access, allowing users to read and write files outside approved paths. This vulnerability affects ImageMagick versions prior to 7.1.2-26 and requires user interaction to exploit—an attacker would need to trick someone into running a specially crafted ImageMagick command. The issue has been resolved in version 7.1.2-26 and later.
- CVE-2022-42479MEDIUM 5.4
TemplateHouse Soledad contains a missing authorization check that allows authenticated users to access functionality they should not have permission to use. An attacker with valid login credentials can bypass access controls to perform actions or view information restricted to higher-privilege accounts. The vulnerability affects Soledad versions up to and including 8.2.5.
- CVE-2022-45813MEDIUM 5.4
BeRocket Advanced AJAX Product Filters versions up to 1.6.3.3 contain a missing authorization flaw that allows authenticated users to perform actions they should not be permitted to access. An attacker with valid login credentials can exploit improperly configured access controls to read or modify data they don't own, though without disrupting service availability. This is a privilege escalation issue affecting WooCommerce sites using this plugin.
- CVE-2023-25969MEDIUM 5.4
A security flaw in ThemeHunk Contact Form & Lead Form Elementor Builder versions up to 1.8.4 fails to properly verify user permissions before allowing certain actions. This means an unauthenticated attacker could potentially manipulate form data or disrupt form functionality by exploiting weak access controls. The vulnerability requires user interaction (such as clicking a malicious link) to be triggered, limiting but not eliminating the risk.
- CVE-2025-63041MEDIUM 5.4
A broken access control vulnerability in the Forget About Shortcode Buttons WordPress plugin (versions 2.1.3 and earlier) allows authenticated users with the contributor role to perform unauthorized actions they should not have permission to execute. This weakness stems from insufficient permission checks on certain functions, enabling contributors to modify or delete content beyond their intended scope.
- CVE-2026-11818MEDIUM 5.4
WPCafe, a popular WordPress plugin for restaurant management, contains a flaw that allows low-privilege users to perform actions restricted to administrators. Specifically, any logged-in user with subscriber access or higher can create, modify, or delete automated notification workflows—a capability meant only for site administrators. The vulnerability exists because the plugin relies on a single check (a REST API nonce) that is publicly visible in the webpage source, making it trivial for any authenticated user to bypass intended restrictions.
- CVE-2026-15320MEDIUM 5.4
Sipeed PicoClaw versions up to 0.2.9 contain a flaw in how it handles configuration reload requests. An authenticated user can manipulate a message parameter to bypass authorization checks, allowing them to modify system behavior or deny service to others. The vulnerability requires an existing login but no special privileges, and exploitation can occur over the network. Public exploit code is available.
- CVE-2026-27351MEDIUM 5.4
Sekander Badsha Crew HRM contains a missing authorization vulnerability that allows authenticated users to perform actions they should not be permitted to perform due to incorrectly configured access controls. An attacker with valid login credentials can exploit weak permission checks to modify data or disrupt availability, even if their role should restrict such access.
- CVE-2026-44794MEDIUM 5.4
Nautobot, a network automation platform, contains a permission bypass vulnerability in its REST API that affects how it validates references between database objects. When users create or update records that link to other objects in the system, the API fails to properly check whether the user has permission to view those referenced objects. This means an authenticated user could potentially reference objects they shouldn't have access to, leading to information disclosure or unintended modifications. The issue affects Nautobot versions before 2.4.33 and 3.1.2.
- CVE-2026-49782MEDIUM 5.4
Elementor Website Builder versions up to 4.1.0 contain a missing authorization flaw that allows authenticated users to perform actions they shouldn't be permitted to perform. An attacker with valid login credentials can exploit incorrectly configured access control settings to gain unauthorized access to sensitive features or data. This is not an unauthenticated attack—the attacker needs a legitimate user account first—but it meaningfully weakens the security boundary between user privilege levels.
- CVE-2026-5139MEDIUM 5.4
Mattermost has a flaw in how it controls access to GitLab integration settings. Any logged-in user can run a slash command (/gitlab connect) to change which GitLab instance the entire Mattermost workspace uses by default. This should only be allowed for administrators. An attacker with any valid Mattermost account could redirect the workspace to a malicious GitLab instance, potentially capturing credentials or injecting compromised code through pull requests and CI/CD pipelines.
- CVE-2026-55432MEDIUM 5.4
Coder, a platform for provisioning remote development environments, contains a flaw in how it handles app sharing permissions within workspaces. When workspace owners create sub-agent applications, the system fails to enforce the administrator-set sharing level limits before saving these apps. This allows a workspace owner to grant broader access to their applications than the organization's policy permits. Attackers must already have workspace owner privileges to exploit this issue, which limits the immediate blast radius but represents a meaningful policy bypass for organizations using Coder to control data exposure.
- CVE-2026-55433MEDIUM 5.4
Coder, a platform for provisioning remote development environments, contains an authorization flaw in its devcontainer rebuild feature. Attackers with valid low-privilege workspace access can trigger a destructive environment rebuild without the proper permission checks, leading to loss of work and service disruption. The vulnerability affects Coder versions before 2.29.7, 2.32.7, 2.33.8, and 2.34.2. A fix has been released that adds the missing authorization validation.
- CVE-2026-56023MEDIUM 5.4
A broken access control vulnerability exists in the UPI QR Code Payment Gateway plugin for WooCommerce affecting versions 1.6.2 and earlier. An authenticated user with low privileges can manipulate payment-related data or operations in ways that should be restricted, potentially altering transaction integrity or customer information. The vulnerability requires an attacker to be logged into the system but does not require additional user interaction to exploit.
- CVE-2026-56696MEDIUM 5.4
OpenHarness contains a vulnerability in its slash command handlers that allows authenticated remote users to inject malicious content into project configuration files. When a user issues /issue or /pr_comments commands, the system fails to validate that these commands come from trusted sources. An attacker with channel access can craft commands that write arbitrary Markdown into sensitive files (.openharness/issue.md and .openharness/pr_comments.md) that get loaded into AI agent system prompts. This creates a persistent injection attack where the agent's behavior is influenced by attacker-controlled instructions on every subsequent run.
- CVE-2026-57291MEDIUM 5.4
The Jenkins Gitee Plugin contains a flaw where permission validation is insufficiently enforced when users attempt to connect to external URLs with stored credentials. An attacker with basic read-level access to a Jenkins instance can exploit this gap to redirect plugin operations to a URL of their choosing and supply credential identifiers they've obtained through separate means. This allows credential reuse or exposure in unintended contexts without proper authorization checks.
- CVE-2026-57294MEDIUM 5.4
Jenkins users should be aware of a credential-exposure vulnerability in the EC2 Fleet Plugin. An attacker with read-only access to Jenkins can exploit a missing permission check to connect to arbitrary URLs and supply pre-obtained AWS credential IDs, potentially allowing them to retrieve sensitive AWS credentials stored within Jenkins. This affects Jenkins EC2 Fleet Plugin version 4.2.3.539.v8fedff2a_81c3 and earlier.
- CVE-2026-57304MEDIUM 5.4
A flaw in Jenkins Assembla Plugin version 1.4 and earlier fails to verify that users should be allowed to configure external connections. An attacker with basic read access to Jenkins can exploit this to create or modify connections to any URL using credentials they control, potentially facilitating reconnaissance, credential theft, or lateral movement into connected systems.
- CVE-2026-57632MEDIUM 5.4
A broken access control vulnerability exists in the Email Marketing for WooCommerce plugin by Omnisend, affecting versions 1.19.0 and earlier. An authenticated user can bypass authorization checks to modify subscriber data or perform other restricted actions. While exploitation requires existing login credentials, the weak access controls mean that any logged-in user—including those with minimal permissions—could escalate their capability to alter email subscriber information or related settings.