The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-47673
MEDIUM
Hono: JWT middleware accepts any Authorization scheme, not only Bearer
CVSS 4.8
CVE-2026-6938
MEDIUM
IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query
CVSS 6.5
CVE-2026-46620
MEDIUM
e107: CSRF in comment.php moderation endpoints via token-optional validation in session_handler::check()
CVSS 6.5
CVE-2026-9484
MEDIUM
SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
CVSS 6.3
CVE-2026-9483
MEDIUM
SourceCodester Student Grades Management System grades.php improper authorization
CVSS 6.3
CVE-2026-9410
MEDIUM
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
CVSS 4.3
CVE-2026-9409
MEDIUM
Sushmi-pal Invoice-System User Management user improper authorization
CVSS 4.3
CVE-2026-9397
HIGH
Besen BS20 EV Charging Station OTA Update Installation improper authorization
CVSS 8.1
CVE-2026-9376
MEDIUM
JPress UCenter Article Submission Endpoint doWriteSave improper authorization
CVSS 6.3
CVE-2026-9306
LOW
QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization
CVSS 3.7
CVE-2026-45187
MEDIUM
Apache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System Jobs
CVSS 6.5
CVE-2026-8786
MEDIUM
Tencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseForInitialization authorization
CVSS 6.3
CVE-2026-8747
MEDIUM
Z-BlogPHP Commend Approval c_system_event.php CheckComment improper authorization
CVSS 6.3
CVE-2026-8743
MEDIUM
Open5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorization
CVSS 6.3
CVE-2026-45365
MEDIUM
Open WebUI: Authenticated users can bypass model access control via exposed query parameter
CVSS 5.4
CVE-2026-45345
MEDIUM
Open WebUI: Missing authorization check at the model update function - models from other users can be updated
CVSS 6.5
CVE-2026-45371
HIGH
SiYuan: SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs
CVE-2026-45147
MEDIUM
SiYuan: Broken access control in SiYuan `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk
CVSS 4.3
CVE-2026-44504
HIGH
Aegra: Cross-user run injection in /threads/{thread_id}/runs (IDOR)
CVE-2026-34656
MEDIUM
Adobe Commerce | Improper Authorization (CWE-285)
CVSS 4.3
CVE-2026-43515
CRITICAL
Apache Tomcat: Security constraints not correctly applied
CVSS 9.1
CVE-2026-43983
HIGH
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
CVSS 8.1
CVE-2026-43912
HIGH
Vaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization
CVSS 8.7
CVE-2026-42876
MEDIUM
External Secrets Operator: Priviledge escalation with secret overwriting
CVSS 4.9
CVE-2026-42875
MEDIUM
External Secrets Operator: Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
Details
Vulnerabilities
1,461
Exploit Likelihood
High