The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,811 vulnerabilities with CWE-862
CVE-2026-54010
HIGH
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVSS 8.3
CVE-2026-56115
HIGH
dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()
CVSS 8.8
CVE-2026-56696
MEDIUM
OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands
CVSS 5.4
CVE-2026-56695
MEDIUM
OpenHarness - Cross-Session Disclosure via /resume and /summary Commands
CVSS 6.5
CVE-2026-56402
MEDIUM
NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Handler
CVSS 6.5
CVE-2026-27604
CRITICAL
FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions
CVE-2026-10609
MEDIUM
Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization
CVSS 6.8
CVE-2026-56280
HIGH
Cap-go - Privilege Inversion in Build Log Stream via SSE Disconnect
CVSS 7.1
CVE-2026-48500
MEDIUM
Filament: Unauthenticated temporary file upload on auth pages
CVSS 6.5
CVE-2026-8934
MEDIUM
Cross-Project Information Leakage in Google App Engine UI
CVE-2026-56104
HIGH
Chainlit < 2.10.1 Session Hijacking via WebSocket Session Restoration
CVSS 8.2
CVE-2026-5139
MEDIUM
GitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration
CVSS 5.4
CVE-2026-56424
HIGH
MISP Core - Cross-Organization Data Modification and Deletion
CVSS 8.8
CVE-2026-56423
HIGH
MISP Core Bulk Deletion - Unauthorized Event Report and Sharing Group Deletion
CVSS 8.8
CVE-2026-44914
HIGH
Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents
CVSS 7.2
CVE-2026-7859
MEDIUM
Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media
CVSS 5.3
CVE-2026-56396
HIGH
phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights()
CVSS 8.8
CVE-2026-56384
MEDIUM
Craft CMS - Missing Authorization in assets/preview-thumb Endpoint
CVSS 4.3
CVE-2026-56341
HIGH
AVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php
CVSS 7.5
CVE-2026-12119
MEDIUM
WordPress Simple File List <= 6.3.7 - Contributor+ Arbitrary File Operations
CVSS 6.5
CVE-2026-11912
HIGH
Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
CVSS 7.5
CVE-2026-56213
MEDIUM
Capgo - Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC
CVSS 5.3
CVE-2026-48582
CRITICAL
Microsoft Exchange Online Elevation of Privilege Vulnerability
CVSS 9.6
CVE-2026-49291
HIGH
mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
CVSS 8.1
CVE-2026-49288
MEDIUM
Statamic CMS < 5.73.23 and 6.x < 6.20.0 - Control Panel Resource Disclosure
CVSS 4.3
Details
Vulnerabilities
8,811
Exploit Likelihood
High