By weakness (CWE)
CWE-863: related vulnerabilities
CVEs classified under CWE-863. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
185 published vulnerabilities · page 2 of 2
- CVE-2026-10211MEDIUM 6.3
AstrBot version 4.23.6 contains a flaw in how it validates file system paths, allowing authenticated users to bypass access restrictions and read, modify, or delete files they shouldn't be able to access. An attacker with valid credentials can exploit this remotely without user interaction. The vulnerability has already been disclosed publicly, and exploit code may be available.
- CVE-2026-10815MEDIUM 6.3
A missing authorization vulnerability was discovered in the Hostel Management System PHP application, specifically in the Admin Dashboard Page's index.php file. An authenticated attacker can manipulate the ID parameter to bypass authorization checks, potentially gaining unauthorized access to sensitive administrative functions. The vulnerability requires valid login credentials but does not require user interaction once authenticated. Public exploit code is available, increasing the practical risk.
- CVE-2026-12797MEDIUM 6.3
A flaw in BerriAI's litellm library (versions up to 1.82.5) allows authenticated users to bypass keyword-based content filtering through manipulation of the prompt parameter in the Completions Interface. An attacker with valid credentials can craft requests that circumvent banned keyword restrictions, potentially exposing the system to restricted content or policy violations. Public exploit code exists for this issue.
- CVE-2026-14716MEDIUM 6.3
A flaw in nextlevelbuilder GoClaw's WebSocket RPC handler allows authenticated users to bypass authorization checks and gain unauthorized access to protected functionality. An attacker with valid credentials can exploit the MethodRouter.Handle function to perform actions they should not have permission to execute, including reading sensitive data or modifying system state. The vulnerability affects versions up to 3.13.0-beta.2 and has been publicly disclosed.
- CVE-2026-15318MEDIUM 6.3
Sipeed PicoClaw, an embedded development board tool, contains a flaw in how it validates user permissions when processing MQTT connections. By manipulating the client ID parameter sent to the MQTT handler, an authenticated attacker can bypass authorization checks and gain unauthorized access to resources they shouldn't reach. The vulnerability affects versions up to 0.2.9 and can be triggered remotely without user interaction once an attacker has valid credentials.
- CVE-2026-15332MEDIUM 6.3
A flaw in zhayujie CowAgent (versions up to 2.1.0) allows authenticated users to perform unauthorized actions through the Message Endpoint. The vulnerability exists in the channel/channel.py component and lacks proper authorization checks, meaning someone with basic login credentials could potentially access or modify data they shouldn't be able to. An exploit has already been published publicly, making active exploitation more likely.
- CVE-2026-44911MEDIUM 6.3
Apache NiFi versions 1.15.0 through 2.9.0 contain an authorization flaw in how configuration verification requests are handled. Users with only read access to component configurations can submit modified configuration properties that override the current settings, effectively letting them invoke verification methods with alternative parameters they shouldn't be allowed to change. This bypasses the intended separation between who can view configurations and who can modify them. The fix requires upgrading to NiFi 2.10.0, which enforces write access requirements for configuration verification requests.
- CVE-2026-47910MEDIUM 6.3
Dreamweaver Desktop versions 21.7 and earlier contain an authorization flaw that allows attackers to read files from your computer that they shouldn't have access to. The attacker must trick you into opening a malicious file, but once you do, they can potentially access sensitive documents and system files. This is a local attack that doesn't require special permissions to execute.
- CVE-2026-54021MEDIUM 6.3
Open WebUI, a self-hosted AI platform designed to run offline, contains a privilege escalation flaw in versions before 0.9.6. Authenticated users can manipulate a path parameter to bypass backend access controls and route requests to Ollama servers they should not be able to reach—including internal systems, higher-privilege backends, or administratively disabled instances. The vulnerability requires a valid user account but no additional authentication or interaction, making it a straightforward post-authentication attack.
- CVE-2026-42998MEDIUM 6.0
OpenStack Keystone contains an authentication bypass vulnerability in its application credential system. An attacker with valid credentials can request a token while impersonating another user by manipulating the user identity in the authentication request. Keystone fails to validate that the requesting user owns the application credential being used, allowing the attacker to obtain a token attributed to a victim account. The token grants access only to projects shared between the attacker and victim, and only with roles that overlap between both users' permissions, but this is still sufficient for account takeover scenarios and audit trail manipulation.
- CVE-2026-42999MEDIUM 6.0
OpenStack Keystone contains a critical authorization bypass vulnerability that allows any authenticated user to escalate their privileges and access resources belonging to other users or projects. The vulnerability stems from a flaw in how Keystone processes policy enforcement—it blindly merges user-supplied JSON request data into the authorization check dictionary, overwriting the trusted database-sourced security context. This means an attacker can simply inject fake user IDs or project IDs into their API request to trick the system into granting them permissions they shouldn't have. The issue affects all versions before 29.0.2 and has existed since Rocky (14.0.0).
- CVE-2026-43000MEDIUM 6.0
An authenticated attacker with basic member-level permissions on an OpenStack Keystone project can escalate their privileges to administrator by chaining two Keystone features—application credentials and trusts—in an unintended way. The attack exploits a validation gap: when an impersonated token is created, Keystone checks the victim's stored admin role assignment in the database rather than validating against the actual permissions on the requesting token. This allows the attacker to create a trust that delegates the victim's admin privileges to themselves. The resulting admin access persists independently and can be maintained through additional credential chains, while all actions appear in audit logs under the victim's identity.
- CVE-2026-44394MEDIUM 6.0
OpenStack Keystone, the identity service underlying many cloud deployments, has a flaw in how it handles federated user logins through SAML2 or OpenID Connect. When a user rescopes a token (essentially asking for a new token with different permissions or projects), the system doesn't carry forward the original token's expiration time. Instead, it issues a fresh token with a standard lifetime. An attacker with valid federated credentials can exploit this by repeatedly rescoping their token just before it expires, effectively creating a token that never truly expires. This bypasses the organization's configured token lifetime policies, allowing indefinite access once initial compromise occurs.
- CVE-2026-12352MEDIUM 5.9
CVE-2026-12352 is a medium-severity authentication bypass vulnerability that allows an attacker to gain access to restricted resources on a device without providing valid credentials. The attacker does not need to be an authenticated user to exploit this flaw, and no user interaction is required. While the vulnerability does not allow attackers to modify or disable systems, it does expose sensitive information to unauthorized parties.
- CVE-2026-13508MEDIUM 5.5
Khoj AI's conversational search platform contains an authorization bypass vulnerability in its conversation sharing feature. By manipulating the conversation.agent parameter, an authenticated user can gain inappropriate access to conversations they shouldn't be able to view or modify. The vulnerability affects Khoj up to version 2.0.0-beta.28 and can be exploited remotely without additional privileges beyond basic authentication. A fix has been proposed but not yet merged into the codebase.
- CVE-2026-21036MEDIUM 5.5
Samsung Internet prior to version 30.0.0.39 contains an authorization flaw that allows a local attacker—someone already with access to the device—to read sensitive information they shouldn't have permission to access. The attacker doesn't need to interact with the user or have elevated system privileges, but they do need to have at least basic local access. This is a confidentiality risk, not a data-destruction or service-disruption issue.
- CVE-2026-48493MEDIUM 5.5
Snipe-IT is an asset management platform used by IT teams to track hardware, software licenses, and inventory. A flaw in versions before 8.6.0 allows a basic user who can only edit their own profile to escalate their own privileges. By sending a specially crafted request to their account settings, they can grant themselves broader permissions—such as the ability to view or create assets, access reports, or perform imports—without needing administrator approval. While admin and superuser roles remain protected, this self-service privilege escalation undermines access controls and could let a low-privilege insider gain visibility into sensitive IT operations data or make unauthorized asset changes.
- CVE-2026-49219MEDIUM 5.5
ImageMagick, widely used for image processing and manipulation, contains a vulnerability that allows a local attacker with login privileges to bypass security policies and read files that should be restricted. The flaw stems from improper handling of filenames, specifically when symlinks are involved. An attacker could exploit this to circumvent the policy restrictions ImageMagick enforces. This is not a remote vulnerability—it requires local system access and user-level permissions.
- CVE-2026-56074MEDIUM 5.5
PraisonAI versions before 1.5.128 have a flaw in how they remember user approval decisions for tool commands. The system caches approval based only on the tool's name, not on what specific arguments or parameters are passed to it. An attacker can trick the system by first getting approval for an innocuous command—like listing a directory—then reuse that cached approval to silently run malicious variations of the same tool, such as exfiltrating API keys or credentials, without prompting the user again. This turns a single benign approval into a gateway for unauthorized data theft.
- CVE-2026-15320MEDIUM 5.4
Sipeed PicoClaw versions up to 0.2.9 contain a flaw in how it handles configuration reload requests. An authenticated user can manipulate a message parameter to bypass authorization checks, allowing them to modify system behavior or deny service to others. The vulnerability requires an existing login but no special privileges, and exploitation can occur over the network. Public exploit code is available.
- CVE-2026-34507MEDIUM 5.4
OpenClaw versions before 2026.4.29 contain a flaw that allows authenticated users to bypass security policies protecting sensitive admin commands. Specifically, attackers can circumvent message delivery restrictions (DM-only policy) and sender authorization checks (allowFrom policy), enabling them to execute administrative functions from contexts or senders that should be blocked. The vulnerability requires an attacker to already have authentication credentials, limiting its blast radius but creating insider risk and account compromise scenarios.
- CVE-2026-42547MEDIUM 5.4
IRIS, a web platform used by incident response teams to collaborate and share investigation details, contains an authorization flaw in versions before 2.4.28 that allows users to create alerts falsely attributed to customers they don't manage. When combined with cross-site scripting vulnerabilities, attackers can also steal alerts belonging to other customers. This means a low-privileged user could pollute another team's alert stream with fraudulent incidents or harvest sensitive investigation data.
- CVE-2026-45692MEDIUM 5.4
Caddy, a popular open-source web server known for automatic HTTPS, contains a path traversal vulnerability affecting versions 2.4.0 through 2.11.2. The vulnerability arises from a disagreement between two critical layers: the authorization system checks permissions using simple text matching, while the configuration API parses the same paths using numerical array indexing. An attacker with valid credentials can exploit this mismatch to access configuration objects they shouldn't be able to reach. For example, a user authorized to view `/config/servers/0` might be able to access `/config/servers/1` by manipulating how indices are parsed. The flaw requires authentication, so it primarily affects scenarios where multiple users or services share a Caddy instance.
- CVE-2026-5069MEDIUM 5.4
The Fluent Forms WordPress plugin contains a flaw that allows subscribers to cancel payment subscriptions belonging to other users. An attacker with basic user access can manipulate a subscription ID parameter to submit cancellation requests for any subscription in the system, potentially disrupting service for legitimate customers. The vulnerability affects versions up to 6.2.1 and requires authentication—a casual visitor cannot exploit it.
- CVE-2026-52779MEDIUM 5.4
OpenProject versions before 17.3.3 and 17.4.1 contain a flaw that allows a project manager in one project to delete shared views (Calendar or Team Planner queries) from another project they shouldn't have access to. The vulnerability stems from the application checking permissions against the wrong project context, then loading the actual view without re-validating ownership. An attacker exploits this by leveraging their legitimate management role in one project to sabotage shared work views in a separate project, disrupting collaboration for other users.
- CVE-2026-55435MEDIUM 5.4
Coder, a platform for provisioning remote development environments via Terraform, has a flaw in how it validates user access to AI Bridge proxy endpoints. The vulnerability allows users whose accounts have been suspended to continue using previously-issued API keys to access those endpoints, because the suspension process doesn't automatically revoke existing tokens. The issue affects Coder versions 2.30.0 through 2.34.1. While this is a real access-control bypass, its practical scope is narrow: it only impacts API keys that were issued before a user's account was suspended, and only until those keys are manually deleted. In most organizations, suspended users have limited outstanding valid keys, and the keys themselves expire over time.
- CVE-2026-56694MEDIUM 5.4
NanoClaw versions before 2.1.0 contain a privilege escalation flaw in how it approves and registers communication channels. A scoped administrator can exploit weak validation in the channel approval process to wire messaging channels into agent groups they don't have permission to access. This allows unauthorized viewing or control of activity in restricted agent groups—essentially letting an admin operate outside their intended scope.
- CVE-2026-56775MEDIUM 5.4
n8n workflow automation platform versions before 1.123.55, 2.25.7, and 2.26.2 contain an authorization flaw in test-run management endpoints. The vulnerability allows authenticated users with read-only viewer permissions to perform state-changing actions—starting new test runs, canceling active runs, and deleting run records—on workflows they should only be able to view. This affects deployments using n8n's Advanced Permissions feature (Enterprise and Cloud editions) with project-based access controls. The flaw stems from incorrect permission scope validation during endpoint authorization.
- CVE-2026-57953MEDIUM 5.4
Mythic, an operations management platform, contains an access control flaw that allows users with spectator-only permissions to perform actions they should not be able to do. Spectators are intended to have read-only visibility, but due to a misconfigured endpoint, they can instead create and delete automation workflows. This means someone with limited access can make unauthorized changes to how operations are automated, potentially disrupting or redirecting workflows. The vulnerability affects versions before 3.4.0.60.
- CVE-2026-58211MEDIUM 5.4
NATS Server versions prior to 2.14.3 and 2.12.12 contain an authentication bypass vulnerability. When a client connects and sends an operation other than the standard CONNECT command first, the parser accepts the connection and registers the client as the configured no_auth_user account. This bypasses user-level restrictions that would normally be enforced during proper authentication, such as connection type limits or proxy requirements. An authenticated attacker could exploit this to assume a privileged account identity without valid credentials.
- CVE-2026-59212MEDIUM 5.4
Open WebUI, a self-hosted AI platform, contains an authorization bypass vulnerability in versions 0.9.6 through 0.9.x that allows users with read-only access to knowledge files to escalate privileges and modify or delete those files. The vulnerability stems from inconsistent access control checks—the system validates read permissions but fails to properly verify write and delete permissions, trusting instead data derived from internal model metadata. An authenticated user can exploit this to upgrade their access level without additional authentication or approval.
- CVE-2026-6269MEDIUM 5.4
GitLab has patched an authorization bypass affecting Community and Enterprise editions. An authenticated developer could modify hidden or restricted merge requests that should have been off-limits to them. The flaw stems from insufficient permission checks when accessing merge requests under certain conditions. While it requires valid credentials and developer-level access, it does allow an insider to tamper with code review artifacts intended to remain confidential or locked.
- CVE-2026-11379MEDIUM 5.3
GitLab Enterprise Edition contains an authorization flaw in its DAST (Dynamic Application Security Testing) site profile feature that allows developers to access secrets they shouldn't be able to reach. Under specific circumstances, a user with a Developer role can retrieve sensitive credentials stored in DAST site profiles—such as authentication tokens or API keys—that are meant to be restricted to higher-privilege users. This affects multiple recent versions of GitLab EE and requires patching to resolve.
- CVE-2026-49397MEDIUM 5.3
Nezha Monitoring, a self-hosted server and website monitoring tool, has a flaw in versions 2.0.0 through 2.0.13 that allows attackers to discover private services that administrators intended to keep hidden. Specifically, services marked as private (with EnableShowInService set to false) can still be enumerated through per-server API endpoints, exposing their names and response timing information. An attacker with network access to a Nezha instance doesn't need credentials to exploit this—they can systematically query endpoints and infer which services exist and how they behave based on timing patterns. This undermines the intended privacy controls.
- CVE-2026-54022MEDIUM 5.3
Open WebUI, a self-hosted AI platform, contains an authorization bypass that allows authenticated users to read private notes belonging to other users. The vulnerability stems from a mismatch between how the access control layer and the storage layer handle document identifiers. While the authorization check looks for note IDs with colons (note:123), the underlying storage system normalizes all colons to underscores (note_123). An attacker who knows or guesses a target user's note ID can simply request it using the underscore format, bypassing the ownership check and receiving the full private note contents. This affects Open WebUI versions before 0.8.11 and requires the attacker to be an authenticated user of the platform.
- CVE-2026-54517MEDIUM 5.3
A flaw in Jackson's data-binding library allows attackers to bypass view-based access controls during JSON deserialization. When a JSON API uses @JsonView annotations to hide certain properties from specific clients or roles, this vulnerability can cause hidden collection or map properties to be populated anyway if they lack a setter method. An attacker sending crafted JSON can inject data into fields that should have been invisible, potentially modifying application state in unintended ways.
- CVE-2026-56152MEDIUM 5.3
Elastic Defend contains an authorization flaw that allows low-privileged authenticated users to view response action data they should not have access to. The vulnerability exploits a gap in access control enforcement, enabling information disclosure under specific conditions. An attacker would need valid credentials and network access to the affected system, but the barrier to exploitation is moderately high due to the required conditions.
- CVE-2026-7765MEDIUM 5.3
Checkmk contains a flaw in how it controls access to user messages through its dashboard feature. When someone shares a dashboard using a public token, the system incorrectly returns messages belonging to the dashboard creator instead of the person viewing it. An attacker who obtains a valid share token can bypass normal access controls and read the creator's private messages directly from the underlying API endpoints—even if no User Messages widget is visible on the dashboard itself. This is an authorization bypass that leaks sensitive information.
- CVE-2026-49983MEDIUM 5.2
Deno is a modern JavaScript/TypeScript runtime that includes permission controls to restrict what programs can access. One of these controls is the env permission, which blocks access to environment variables. You can use --deny-env to prevent this entirely, or --allow-env=FOO,BAR to restrict access to specific variables. However, in versions before 2.8.1, a built-in function called process.loadEnvFile() bypasses this protection. This function loads environment variables from a .env file, but it only checks whether the program can read the file—it ignores whether env access is allowed. This means an attacker who can control or create a .env file on the system, combined with read access (--allow-read), can inject environment variables into a sandboxed program that was supposed to have no env access. The vulnerability is patched in version 2.8.1.
- CVE-2026-13484MEDIUM 5.0
MLflow, a popular open-source platform for managing machine learning workflows, contains an authorization flaw in its experiment-scoped label schema API. An authenticated user with low privileges can manipulate this API endpoint to perform actions they should not be allowed to perform—specifically, reading, modifying, or deleting label schemas—without proper permission checks. The vulnerability requires an attacker to already have valid login credentials and involves moderately complex attack conditions, making it a practical but not trivial risk.
- CVE-2026-14340MEDIUM 5.0
GitHub Enterprise Server had a flaw in how it validated permissions for tokens used by GitHub Apps. A user-to-server token tied to a GitHub App could be abused to create issues, comments, and vulnerability reports on public repositories even if the token was not supposed to have access to those repositories. An attacker who stole such a token could post content as the legitimate user, making it appear the user performed those actions. GitHub has patched this across all supported versions.
- CVE-2026-44173MEDIUM 5.0
MariaDB server versions within specific ranges contain a privilege-escalation flaw that allows authenticated users to write files to the server's filesystem without possessing the FILE privilege. The vulnerability exists when SELECT statements direct output to files (using INTO OUTFILE or INTO DUMPFILE) and the FROM clause references only subqueries, bypassing the privilege check. An attacker with database login credentials but no explicit FILE permission can exploit this to write arbitrary content to disk, potentially compromising system integrity or enabling further attacks.
- CVE-2026-10741MEDIUM 4.9
Sonatype Nexus Repository Manager versions before 3.93.0 have a flaw that allows repository administrators with delegated authority to access upstream proxy credentials that should be protected. When a Nexus instance is configured to proxy external repositories, it stores credentials needed to authenticate with those upstream servers. An administrator with limited permissions—one who manages only specific repositories—can exploit this vulnerability to retrieve credentials that should remain hidden even from them. This is a credential disclosure issue with medium severity that requires administrator-level access to exploit.
- CVE-2026-41280MEDIUM 4.9
Apache DolphinScheduler contains an authorization flaw that allows authenticated users with system login privileges to delete task definitions in projects they shouldn't have access to. The vulnerability arises from insufficient permission checks when handling task definition deletion requests. An attacker with valid system credentials could exploit this to disrupt workflow orchestration by removing critical task definitions from other projects, potentially causing operational disruption. The issue is limited to versions before 3.4.2 and requires existing system access to exploit.
- CVE-2026-10616MEDIUM 4.3
GoClaw, a component of nextlevelbuilder, contains a flaw in how it validates permissions when completing team tasks. An authenticated attacker can manipulate the Team Task Completion Handler to bypass authorization checks, potentially modifying task records they shouldn't have access to. The vulnerability requires a valid login and network access, and affects versions up to 3.11.3. While the issue carries a medium risk profile, the public availability of exploit details increases practical attack likelihood.
- CVE-2026-12446MEDIUM 4.3
Google Chrome versions before 149.0.7827.155 contain a flaw in how passwords are handled that allows attackers to trick users into visiting a malicious website, which can then leak sensitive information from other websites the user has visited. The vulnerability requires user interaction—specifically clicking a link or visiting a crafted page—but does not require the user to install anything or be an administrator. Once triggered, an attacker gains access only to what the browser can see, not the user's entire system.
- CVE-2026-15286MEDIUM 4.3
A WordPress plugin called Gutenberg Blocks with AI by Kadence WP contains a flaw that allows contributors—users with limited publishing rights—to bypass the approval process and publish posts immediately without administrator review. The vulnerability exists in a REST API endpoint used for processing patterns, where the permission check was not properly configured. This affects all versions up to and including 3.5.32.
- CVE-2026-2470MEDIUM 4.3
The Pagelayer WordPress page builder plugin contains an authorization flaw that allows contributors and above to secretly configure contact form email templates by exploiting a mismatch between how the plugin saves settings and how it uses them. A low-level authenticated user can inject malicious form templates via the plugin's settings API, then those templates get processed by the public-facing contact form endpoint without checking who set them up or whether the post is actually published. This enables attackers to manipulate how contact form emails are sent, which becomes especially dangerous if chained with other vulnerabilities.
- CVE-2026-27761MEDIUM 4.3
Gitea, a self-hosted Git platform, contains a flaw in how it validates API permissions on feed endpoints. Specifically, the RSS and Atom feed features for repositories do not properly enforce token scope restrictions. This means a token that lacks permission to access a private repository can still retrieve sensitive commit information by accessing the feed endpoints directly. The issue affects Gitea versions up to 1.26.2.
- CVE-2026-32906MEDIUM 4.3
OpenClaw versions prior to 2026.5.12 contain a privilege escalation flaw in their Slack plugin approval system. Users who hold limited exec approval permissions can manipulate the approval workflow to bypass intended authorization checks, allowing them to approve plugin actions that should require additional oversight or operator configuration. The vulnerability requires an authenticated user to exploit, reducing but not eliminating risk in environments with permissive access controls.
- CVE-2026-40914MEDIUM 4.3
Apache Artemis has a flaw in how it enforces permissions when users communicate via the STOMP protocol. A user with permission to send or receive messages on a particular address can trick the system into accepting messages with a message routing-type that the address doesn't normally support. This bypasses an important security boundary: only administrators with explicit createAddress permission should be able to change an address's routing-type capabilities. An attacker could exploit this to send or consume messages in ways that violate the intended security policy, even though their basic send/consume permissions are legitimate.
- CVE-2026-44169MEDIUM 4.3
MariaDB's access control for stored routines has a flaw that leaks routine definitions to users who shouldn't see them. If a user receives EXECUTE permission on a stored routine through a database role, they can view the routine's source code without having explicit SHOW CREATE ROUTINE privilege. This bypasses the intended separation between execution rights and visibility rights, allowing unauthorized code inspection. The issue affects MariaDB 11.4, 11.8, and 12.3 releases across a specific version range and has been patched.
- CVE-2026-45563MEDIUM 4.3
Roxy-WI, a popular web management interface for load balancers and web servers, contains a flaw that allows any logged-in user to view detailed audit trails of other users' administrative actions. Even a guest-level user in one department can see which servers another user has accessed, what configuration changes they deployed, and what services they restarted. The vulnerability affects Roxy-WI versions 8.2.6.4 and earlier. While this doesn't grant direct control over infrastructure, it exposes sensitive operational history that should remain confidential.
- CVE-2026-47236MEDIUM 4.3
Solidtime, an open-source time-tracking application, contains an authorization bypass vulnerability in its team management interface. Prior to version 0.12.2, the web page that displays team members and pending invitations fails to properly enforce permission checks, allowing any employee in the organization to view sensitive information—including pending invitation email addresses and member lists—even though the same data is correctly restricted in the official API. The vulnerability stems from incomplete permission validation in the Jetstream page handler, which checks only basic team membership rather than the required invitations:view and members:view permissions.
- CVE-2026-49288MEDIUM 4.3
Statamic, a Laravel-based content management system, contained an authorization flaw that allowed authenticated users with Control Panel access to view content and metadata they weren't supposed to see. An attacker with valid login credentials could browse restricted entries, assets, user profiles, roles, and groups—exposing titles, custom field values, entry content, asset metadata, and the mere existence of sensitive organizational structures. The vulnerability is read-only; attackers could not modify data. Fixed in Statamic 5.73.23 and 6.20.0.
- CVE-2026-49369MEDIUM 4.3
JetBrains YouTrack versions before 2026.1.13162 contained a flaw that allowed authenticated users to access sensitive information about other users and groups they shouldn't be able to see. The vulnerability is limited to the Users and Groups administrative pages and requires valid login credentials to exploit. This is a straightforward authorization issue where the application failed to properly restrict who could view certain user and group data.
- CVE-2026-52795MEDIUM 4.3
Gogs, a self-hosted Git service, contains a logic error in its Watch API that allows any authenticated user to monitor private repositories they should not have access to. The vulnerability stems from an inverted access check—the API returns an error when a user CAN read the repository, rather than when they CANNOT. Once a user watches a private repository, their dashboard reveals sensitive information including commit messages, branch names, issue titles, and pull request details. If email notifications are enabled, attackers also receive email digests containing issue and comment content from repositories they should be excluded from.
- CVE-2026-53835MEDIUM 4.3
OpenClaw versions before 2026.5.6 have a flaw in how they enforce configuration rules for Feishu dynamic-agent bindings. An authenticated user can create or modify these bindings while bypassing the normal access controls that should restrict who can make such changes. This means someone with legitimate credentials could potentially create unauthorized connections between senders and agents that policy should have blocked.
- CVE-2026-55873MEDIUM 4.3
SeaweedFS versions 4.08 through 4.33 contain an authorization flaw in their S3Tables integration. When requests use AWS SigV4 signing for the S3Tables service, the system incorrectly maps low-privileged user identities to a shared administrator account instead of enforcing proper access controls. This misconfiguration allows authenticated users with basic S3 permissions to discover confidential information—specifically, the names and Amazon Resource Names (ARNs) of table buckets managed by administrators. The vulnerability requires valid AWS credentials to exploit and is limited to information disclosure; no data modification or system disruption is possible. SeaweedFS 4.34 and later versions resolve this issue.
- CVE-2026-5796MEDIUM 4.3
GitLab has patched a flaw affecting multiple versions of its Community Edition (CE) and Enterprise Edition (EE) where an authenticated user with Reporter-level permissions in a group could view package metadata even when the Package Registry feature was disabled at the project level. The issue stems from incomplete authorization logic that failed to properly enforce registry access controls, allowing information disclosure without requiring higher privileges or user interaction.
- CVE-2026-58209MEDIUM 4.3
NATS Server has a flaw in how it enforces message access controls when delivering retained messages and replaying durable messages over MQTT. Specifically, the server fails to consistently verify that a subscriber's deny rules should block a message before delivering it. An authenticated attacker with subscriber access could receive messages they should not have access to because the server bypasses access checks during certain message delivery scenarios. This affects versions before 2.14.3 and 2.12.12.
- CVE-2026-58214MEDIUM 4.3
A flaw in NATS Server versions before 2.14.3 and 2.12.12 allows an authenticated MQTT client to bypass configured access controls and subscribe to internal system topics that handle MQTT quality-of-service acknowledgments. This exposes sensitive protocol metadata about other MQTT sessions in the account, but does not allow modification or disruption of services.
- CVE-2026-59217MEDIUM 4.3
Open WebUI before version 0.10.0 contains an authorization bypass flaw that allows read-only users of a knowledge base to upload files and attach them to knowledge bases they shouldn't be able to modify. When users upload files, the application accepts a metadata parameter specifying which knowledge base to link the files to, but fails to check whether the uploading user actually has write access to that knowledge base. This lets lower-privilege users escalate their capabilities within the platform by injecting content into knowledge bases they can only read.
- CVE-2026-59227MEDIUM 4.3
Open WebUI, a self-hosted AI platform, contains an authorization bypass vulnerability in its image-editing API endpoint. Prior to version 0.10.0, any verified user could invoke server-side image editing operations without permission checks, even if administrators had disabled the feature globally or restricted it at the user level. This allowed non-admin users to consume server resources and leverage admin-configured AI provider credentials for image manipulation tasks they should not have access to.
- CVE-2026-5952MEDIUM 4.3
GitLab has patched a privilege escalation weakness in its Community and Enterprise editions that allowed developers to bypass package protection rules and modify Maven package metadata they shouldn't have been able to access. The flaw required an authenticated account with developer permissions and affected versions 17.11 through 18.11.5, 19.0.0 through 19.0.2, and 19.1.0. Attackers couldn't steal data or crash systems, but they could alter package contents in repositories that should have been locked down.
- CVE-2026-6277MEDIUM 4.3
GitLab EE contains an authorization bypass that allows authenticated users with Security Manager role to modify project security settings even when that feature is supposed to be disabled. An attacker with this role can circumvent intended access controls to manage security configurations that should be locked down, potentially weakening project defenses.
- CVE-2026-9048MEDIUM 4.3
Slider Revolution, a popular WordPress plugin, contains a vulnerability that allows authenticated users with basic contributor privileges to view sensitive social media API credentials through a specific AJAX action. An attacker with contributor-level access or higher can call the 'slider.get.full' AJAX action to retrieve raw API tokens and keys—including Instagram OAuth tokens, Flickr API keys, YouTube Data API credentials, and Facebook App IDs—that have been configured within slider settings. This exposure affects plugin versions 7.0.0 through 7.0.14.
- CVE-2026-9791MEDIUM 4.3
An authenticated user who belongs to a Keycloak organization can request tokens or access APIs in ways that expose organization metadata, even after an administrator has turned off the Organizations feature. This metadata leakage could cause downstream applications (resource servers) to make incorrect access control decisions based on stale or unintended organization information.
- CVE-2026-9807MEDIUM 4.3
GitLab has patched a flaw in its Community and Enterprise editions where a Project Access Token that was supposed to be blocked could still access private project resources. This happened because the authorization checks weren't applied correctly when a token was revoked or blocked. An authenticated user with permissions to create or manage tokens could potentially exploit this before the fix was released, though the vulnerability requires prior login access and the attacker would need knowledge of or ability to create a blocked token.
- CVE-2026-14896MEDIUM 4.2
HashiCorp Nomad has an authorization flaw in its dynamic host volumes feature that allows an operator with volume deletion rights in one namespace to delete volume claims belonging to jobs in a different namespace. This cross-namespace bypass undermines the multi-tenant isolation model that Nomad administrators rely on to prevent unauthorized access across organizational boundaries. The vulnerability affects both community and enterprise editions across multiple versions.
- CVE-2026-46730MEDIUM 4.2
Dell PowerProtect Data Domain contains an authorization flaw that allows a high-privileged local attacker to execute commands they shouldn't be able to run. The vulnerability affects multiple release branches spanning versions 7.7.1.0 through 8.7, and while it requires someone with elevated access and physical/local connectivity to the system, it could lead to unauthorized actions within the backup infrastructure.
- CVE-2026-48776MEDIUM 4.2
A path traversal vulnerability in LangGraph Python SDK versions 0.3.14 and earlier allows authenticated users to manipulate resource identifiers in HTTP requests, potentially accessing or modifying resources they shouldn't have permission to reach. The vulnerability stems from unsafe construction of URL paths using caller-supplied identifiers without proper sanitization. An attacker with valid credentials could craft specially formatted identifier values containing URL path characters to bypass authorization checks, particularly in deployments where access control relies on URL-prefix validation rather than application-level authorization.
- CVE-2026-53860MEDIUM 4.2
OpenClaw versions before 2026.5.7 contain a flaw in the BlueBubbles feature that allows authenticated users to bypass sender identity verification. Instead of confirming the actual sender, the system can be tricked into matching allowlist rules based on conversation metadata—data that attackers can influence. This means an attacker with legitimate access could manipulate conversation identifiers to receive responses that should only go to authorized senders, effectively circumventing access controls meant to restrict agent functionality.
- CVE-2026-0934LOW 3.8
GitLab EE contains a flaw in how it enforces CI/CD visibility settings on protected environment configurations. An authenticated user with a custom role—even one granted limited permissions—can bypass CI/CD visibility controls to view, create, or delete protected environment settings that should be hidden from them. This affects specific version ranges and requires the attacker to already have some level of authentication and role assignment within the GitLab instance.
- CVE-2026-53809LOW 3.8
OpenClaw versions prior to 2026.4.25 contain a policy bypass flaw that weakens access controls for bundled development tools. When an attacker has local access to a system running the embedded runner feature, they can use provider aliases (alternative names for tool repositories) to bypass intended restrictions on which tools they're allowed to use. The vulnerability is context-specific—it only affects configurations where this feature is explicitly enabled—but it does allow unauthorized tool selection outside policy boundaries.
- CVE-2026-8074LOW 3.8
Mattermost has a permission enforcement gap in its user status management API. A User Manager with write access to user management—but explicitly without access to manage integrations or bots—can deactivate bot accounts by directly calling the user active status endpoint. This should not be possible; the API should reject such requests from users lacking bot management permissions. The vulnerability affects Mattermost Server versions 11.7.0 and earlier in the 11.7.x branch, and 10.11.17 and earlier in the 10.11.x branch.
- CVE-2026-8823LOW 3.8
Mattermost has a permission validation flaw affecting versions 11.7.0 and 10.11.x up to 10.11.17. When an administrator with limited privileges attempts to demote a user to guest status, the system fails to properly verify whether the target is a bot account. This oversight allows a lower-privileged admin to degrade arbitrary bot accounts—including those managed by higher-privileged administrators—through the standard user demotion API. The impact is confined to integrity and availability concerns within the messaging platform.
- CVE-2026-41852LOW 3.7
Spring Expression Language (SpEL) in VMware Spring Framework contains a flaw that allows attackers to invoke arbitrary methods with zero arguments even in contexts designed to restrict or prevent such actions. An attacker with network access could exploit this to trigger unintended application logic, potentially leading to denial of service or information disclosure depending on available methods and application design. This affects multiple versions across the 5.3, 6.1, 6.2, and 7.0 release branches.
- CVE-2026-3553LOW 3.1
GitLab Community Edition and Enterprise Edition contain an authorization flaw that allows authenticated users to view confidential issue details they should not have access to. The vulnerability affects versions 12.0 through 18.10.7, 18.11.0 through 18.11.4, and 19.0.0 through 19.0.1. An attacker must already have valid GitLab credentials to exploit it, and success depends on specific configuration or state conditions. While the exposure is limited to reading sensitive issue metadata rather than system compromise, it represents a meaningful confidentiality breach for organizations using affected versions.
- CVE-2026-45426LOW 3.1
Apache Airflow's log server uses a flawed string-matching approach to authorize workers' access to task logs. Instead of checking if a worker's JWT token matches a specific Dag name exactly, the system strips characters from the left side of requested Dag names in a way that can match multiple unintended Dags. An authenticated worker with a token for 'dag_a' could read logs from 'dag_attacker', 'aaaa_target', or '_dag_secret'—any Dag whose name starts with characters found in 'dag_a'. This breaks the intended per-Dag log isolation in multi-team environments.
- CVE-2026-59226LOW 3.1
Open WebUI versions 0.9.0 through 0.9.x contain a privilege and access control flaw where deactivated users can still trigger scheduled automation tasks and access AI models they should no longer have permission to use. The vulnerability stems from insufficient re-validation when executing stored automations and overly lenient model access checks. An attacker with a deactivated account could potentially continue running automations or accessing restricted models until the account is fully removed from the system.
- CVE-2026-6352LOW 2.7
GitLab Enterprise Edition contains an authorization flaw that allows authenticated users with auditor-level access to modify compliance violation records through GraphQL API calls. The vulnerability affects multiple version branches and requires high privilege credentials to exploit, limiting real-world impact to insider threats or compromised admin accounts.
- CVE-2026-8800LOW 2.7
Progress MOVEit Transfer contains an authorization flaw in its Audit User module that allows high-privileged users to access information they shouldn't have permission to see. The vulnerability is limited in scope—it only exposes confidential data, does not allow modification or deletion, and requires an authenticated account with elevated privileges to exploit. Most organizations running recent versions are either already patched or face minimal risk from this issue.
- CVE-2026-50266LOW 2.2
A flaw in OpenStack Neutron versions before 28.0.1 allows project managers to perform network spoofing attacks on shared networks. The vulnerability stems from overly permissive role-based access control (RBAC) policies that allow any project manager to create or modify ports on networks they don't own, and crucially, to assign those ports special "trusted" network service identities (like DHCP servers). This bypasses normal anti-spoofing rules and security group protections, enabling attackers to spoof DHCP, MAC, or IP addresses to target other tenants sharing the same network. This is a reintroduction of a vulnerability that was supposedly fixed nearly a decade ago.
- CVE-2026-46549LOW 2.0
NocoDB, a spreadsheet-like database platform, contained a flaw in how it handled OAuth token permissions. When administrators issued OAuth tokens with intentionally restricted scopes—such as limiting access to specific features or databases—the system failed to actually enforce those restrictions. A user with such a restricted token could gain access to resources and perform actions far beyond what the token was meant to allow, effectively inheriting the full permissions of the underlying user account. This issue has been patched in version 2026.04.1.