The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-13490
LOW
glpi-project glpi Document document.send.php canViewFile authorization
CVSS 3.7
CVE-2026-49278
MEDIUM
Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation
CVSS 6.7
CVE-2026-56310
MEDIUM
Cap-go - Authorization Bypass in Organization Members Endpoint via API Key Scope Bypass
CVSS 4.3
CVE-2026-56231
HIGH
Capgo - Broken Object Level Authorization in Build Job Control via jobId Parameter
CVSS 7.6
CVE-2026-46552
MEDIUM
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
CVSS 5.8
CVE-2026-54012
HIGH
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVSS 7.1
CVE-2026-56311
MEDIUM
Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC
CVSS 5.3
CVE-2026-12799
MEDIUM
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
CVSS 4.3
CVE-2026-12797
MEDIUM
BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
CVSS 6.3
CVE-2026-12771
MEDIUM
BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
CVSS 5.0
CVE-2026-12770
MEDIUM
BerriAI litellm Admin Key key_management_endpoints.py improper authorization
CVSS 5.4
CVE-2026-56295
MEDIUM
Capgo - Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API Keys
CVSS 6.3
CVE-2026-12673
MEDIUM
Liquidfiles < 4.2.12 - Improper Authorization
CVE-2026-48089
HIGH
DevGuard has improper authorization on public assets
CVE-2026-49338
HIGH
Sentriz Gonic < 0.21.0 - Authenticated Private Playlist Disclosure and Deletion
CVSS 7.1
CVE-2026-50201
MEDIUM
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVSS 6.5
CVE-2026-20190
HIGH
Cisco Identity Services Engine Information Disclosure Vulnerability
CVSS 7.5
CVE-2026-12213
MEDIUM
hcengineering Huly Platform User Information operations.ts getAccountInfo improper authorization
CVSS 4.3
CVE-2026-12204
HIGH
ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization
CVSS 7.3
CVE-2026-12190
MEDIUM
Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme
CVSS 5.3
CVE-2026-12189
MEDIUM
Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
CVSS 5.3
CVE-2026-49397
MEDIUM
Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVSS 5.3
CVE-2026-44208
MEDIUM
Frappe: IDOR in `submit_discussion()`
CVE-2026-12065
LOW
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
CVSS 1.8
CVE-2026-47342
HIGH
Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
CVSS 8.8
Details
Vulnerabilities
1,461
Exploit Likelihood
High