The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-15471
MEDIUM
Eleveo Call Recording Software pci_dss_status.jsp improper authorization
CVSS 4.3
CVE-2026-15470
MEDIUM
Eleveo Call Recording Software group.jsp improper authorization
CVSS 4.3
CVE-2026-56240
MEDIUM
Capgo - Billing Authorization Bypass via Exhausted Usage Credits
CVSS 4.3
CVE-2026-55664
MEDIUM
Grist: Insufficient access control in the /forms endpoint exposes table metadata
CVSS 4.3
CVE-2026-15377
MEDIUM
Eleveo Call Recording Software sendlogfile improper authorization
CVSS 4.3
CVE-2026-15376
MEDIUM
Eleveo Call Recording Software statisticReportAction.do improper authorization
CVSS 6.3
CVE-2026-15375
MEDIUM
Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization
CVSS 4.3
CVE-2026-15374
MEDIUM
Eleveo Call Recording Software Group roleAddAction.do improper authorization
CVSS 6.3
CVE-2026-15373
MEDIUM
Eleveo Call Recording Software userAddAction.do improper authorization
CVSS 6.3
CVE-2026-15318
MEDIUM
Sipeed PicoClaw MQTT Channel mqtt.go authorization
CVSS 6.3
CVE-2026-55212
HIGH
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
CVSS 7.1
CVE-2026-59226
LOW
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVSS 3.1
CVE-2026-15191
MEDIUM
mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization
CVSS 6.3
CVE-2026-58252
MEDIUM
NATS Server: Subscribe Authz Bypass via Wildcard-Overlap
CVSS 6.5
CVE-2026-58251
MEDIUM
NATS Server: Queue Subscribe Authz Bypass
CVSS 6.5
CVE-2026-15036
MEDIUM
Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization
CVSS 4.3
CVE-2026-56293
MEDIUM
Capgo - Stale Cross-Organization Authorization via Incomplete deploy_history Update in transfer_app()
CVSS 5.4
CVE-2026-56246
HIGH
Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege Inheritance
CVSS 8.1
CVE-2026-55428
HIGH
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
CVSS 8.2
CVE-2026-55077
HIGH
Coder: User-admin role can reset owner account password
CVSS 7.2
CVE-2026-46700
MEDIUM
Actual < 26.6.0 - Bank-Sync Secret Enumeration via GET /secret/:name
CVSS 4.3
CVE-2026-34048
CRITICAL
Coolify < 4.0.0-beta.471 - Low-Privileged Terminal Command Execution
CVSS 9.9
CVE-2026-44362
MEDIUM
OP-TEE's subkey rollback protection can be bypassed with older subkey versions
CVSS 5.5
CVE-2026-14794
MEDIUM
Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper authorization
CVSS 4.3
CVE-2026-14793
MEDIUM
Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization
CVSS 4.3
Details
Vulnerabilities
1,461
Exploit Likelihood
High