The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-16075
MEDIUM
AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
CVSS 4.3
CVE-2026-49977
MEDIUM
tarteaucitron.js: data-cookie attribute can be used to delete arbitrary cookies
CVSS 4.3
CVE-2026-61718
MEDIUM
bunkerweb: Read-only Web UI users can delete job cache files due to missing authorization on /cache/ routes
CVSS 5.4
CVE-2026-15909
MEDIUM
RafyMrX TOKO-ONLINE-ROTI add.php authorization
CVSS 6.3
CVE-2026-53515
HIGH
Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/sso
CVSS 7.1
CVE-2026-45337
HIGH
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
CVSS 7.6
CVE-2026-49997
MEDIUM
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
CVSS 5.4
CVE-2026-58540
HIGH
Microsoft Windows 10 Version 1607 - Windows Installer Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-58277
HIGH
Microsoft SharePoint Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-54121
HIGH
Microsoft Windows 10 Version 1607 - Active Directory Certificate Services Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-50346
HIGH
Microsoft Windows 10 Version 1607 - Netlogon RPC Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50344
HIGH
Microsoft Windows 10 Version 1607 - Windows OLE Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-58631
HIGH
Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-49170
HIGH
Windows StateRepository API Server file Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-15622
MEDIUM
poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
CVSS 5.3
CVE-2026-15594
LOW
waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization
CVSS 3.7
CVE-2026-15516
MEDIUM
MacCMS Pro Installation Index.php step5 authorization
CVSS 5.6
CVE-2026-15510
MEDIUM
Leantime API saveSetting improper authorization
CVSS 6.3
CVE-2026-15509
MEDIUM
Leantime JSON-RPC Endpoint addUser improper authorization
CVSS 6.3
CVE-2026-56313
HIGH
Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint
CVSS 8.1
CVE-2026-56241
HIGH
Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right
CVSS 8.3
CVE-2026-15499
MEDIUM
AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization
CVSS 6.3
CVE-2026-15474
MEDIUM
Eleveo Call Recording Software audio.jsp improper authorization
CVSS 4.3
CVE-2026-15473
MEDIUM
Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization
CVSS 6.3
CVE-2026-15472
MEDIUM
Eleveo Call Recording Software composeEmailAction.do improper authorization
CVSS 4.3
Details
Vulnerabilities
1,461
Exploit Likelihood
High