The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,362 vulnerabilities with CWE-863
CVE-2026-13484
MEDIUM
MLflow Experiment-scoped Label Schema CRUD API authorization
CVSS 5.0
CVE-2026-58056
HIGH
RustDesk - FileTransfer Session Authorization Scope Bypass
CVSS 7.6
CVE-2026-53577
MEDIUM
Kestra: Cross-Execution File Read via Preview Endpoint (IDOR)
CVSS 6.5
CVE-2026-55189
HIGH
RustFS: FTP frontend skips IAM authorization on object reads
CVSS 7.7
CVE-2026-55188
HIGH
RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials
CVSS 8.2
CVE-2026-52779
MEDIUM
OpenProject Calendar and Team Planner - Cross-Project Authorization Bypass
CVSS 5.4
CVE-2026-44735
MEDIUM
OpenProject: Shares API Information Disclosure
CVSS 6.5
CVE-2026-9640
HIGH
Canonical - LXD Snapshot Import Privilege Escalation Vulnerability
CVSS 7.2
CVE-2026-54096
HIGH
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
CVSS 8.4
CVE-2026-54091
HIGH
File Browser: Incorrect access control in public directory shares via rule path rebasing
CVSS 7.5
CVE-2026-55411
MEDIUM
ToolJet < 3.20.1780-lts - Cross-Tenant Credential Decryption
CVSS 6.8
CVE-2026-54573
MEDIUM
Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy
CVE-2026-5952
MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-5796
MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-11379
MEDIUM
Incorrect Authorization in GitLab
CVSS 5.3
CVE-2026-0934
LOW
Incorrect Authorization in GitLab
CVSS 3.8
CVE-2026-52808
HIGH
Gogs: Write-level collaborators can mutate admin-only repository settings via API
CVSS 7.1
CVE-2026-52795
MEDIUM
Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activity
CVSS 4.3
CVE-2026-56232
HIGH
Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header
CVSS 8.8
CVE-2026-48493
MEDIUM
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
CVSS 5.5
CVE-2026-54518
MEDIUM
jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind
CVSS 6.5
CVE-2026-54517
MEDIUM
jackson-databind: @JsonView bypass for setterless creator properties
CVSS 5.3
CVE-2026-46549
LOW
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVSS 2.0
CVE-2026-23513
HIGH
FOSSBilling: Broken Authorization in Client Transaction and Order Listings
CVE-2026-54761
HIGH
Traefik < 3.6.21 and 3.7.0-ea.1-3.7.4 - Gateway Namespace Bypass
CVSS 7.1
Details
Vulnerabilities
3,362
Exploit Likelihood
High