The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-14538
MEDIUM
BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox
CVE-2026-48499
CRITICAL
Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache
CVE-2026-23981
MEDIUM
Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification
CVE-2026-41187
MEDIUM
Calico Tier Authorization Bypass via DeleteCollection
CVE-2026-66488
MEDIUM
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVSS 5.3
CVE-2026-18207
MEDIUM
Keycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching
CVSS 6.5
CVE-2026-47726
HIGH
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
CVE-2026-61487
MEDIUM
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
CVSS 6.5
CVE-2026-64743
MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 6.5
CVE-2026-64711
MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-43792
MEDIUM
Apple Safari and macOS < 26.6 - Unprotected User Data Exposure via Authorization State Management Flaw
CVSS 6.5
CVE-2026-43775
MEDIUM
macOS <15.7.8 and <26.6 - Unprotected User Data Exposure via Authorization State Management Flaw
CVSS 5.5
CVE-2026-43756
MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Sensitive User Data Exposure
CVSS 5.5
CVE-2026-64642
HIGH
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
CVSS 8.2
CVE-2026-17531
MEDIUM
unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization
CVSS 5.0
CVE-2026-17530
MEDIUM
AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization
CVSS 6.3
CVE-2026-17529
MEDIUM
AstrBotDevs AstrBot astr_main_agent.py authorization
CVSS 6.3
CVE-2026-17434
MEDIUM
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
CVSS 6.3
CVE-2026-17433
MEDIUM
nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization
CVSS 5.3
CVE-2026-62835
CRITICAL
Azure Portal Information Disclosure Vulnerability
CVSS 9.3
CVE-2026-56160
CRITICAL
Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
CVSS 9.1
CVE-2026-62563
MEDIUM
Oracle Work IN Process < 12.2.15 - Improper Authorization
CVSS 5.4
CVE-2026-62444
MEDIUM
Oracle Contracts Integration < 12.2.15 - Improper Authorization
CVSS 6.1
CVE-2026-61082
MEDIUM
MySQL Connectors 9.7.0-9.7.1 - Unauthenticated Unauthorized Data Access via Connector/J
CVSS 6.5
CVE-2026-60957
MEDIUM
Oracle Transportation Execution 12.2.3-12.2.15 - Cross-Site Request Forgery via HTTP with Scope Change Impact
CVSS 5.4
Details
Vulnerabilities
1,461
Exploit Likelihood
High