The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,363 vulnerabilities with CWE-863
CVE-2026-49288
MEDIUM
Statamic CMS < 5.73.23 and 6.x < 6.20.0 - Control Panel Resource Disclosure
CVSS 4.3
CVE-2026-47339
HIGH
Apache APISIX: authz-casdoor incorrect session sharing
CVSS 8.1
CVE-2026-56075
HIGH
PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override
CVSS 8.8
CVE-2026-56074
MEDIUM
PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching
CVSS 5.5
CVE-2026-10741
MEDIUM
Sonatype Nexus Repository Manager < 3.93.0 - Proxy Credential Disclosure
CVSS 4.9
CVE-2026-54803
CRITICAL
WordPress SMS Alert Order Notifications plugin <= 3.9.4 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-48781
CRITICAL
Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
CVSS 9.9
CVE-2026-42357
MEDIUM
Apache DolphinScheduler < 3.4.2 - Unauthorized Workflow Instance Access
CVSS 6.5
CVE-2026-41280
MEDIUM
Apache DolphinScheduler < 3.4.2 - Unauthorized Task Definition Deletion
CVSS 4.9
CVE-2026-32967
CRITICAL
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CVSS 9.1
CVE-2026-32966
CRITICAL
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
CVSS 9.8
CVE-2026-12446
MEDIUM
Google Chrome < 149.0.7827.155 - Cross-Origin Data Leak via Passwords Implementation
CVSS 4.3
CVE-2026-48776
MEDIUM
langchain-ai - LangGraph SDK Has Unsafe URL Path Construction
CVSS 4.2
CVE-2026-53860
MEDIUM
OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles
CVSS 4.2
CVE-2026-53855
HIGH
OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks
CVSS 8.1
CVE-2026-53854
MEDIUM
OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands
CVSS 6.5
CVE-2026-53853
HIGH
OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOS
CVSS 8.3
CVE-2026-5149
MEDIUM
RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter
CVSS 6.5
CVE-2026-47777
HIGH
Mastodon has a consent-check bypass in its remote Collections
CVSS 7.5
CVE-2026-34023
HIGH
Wertheim SafeController 6.15.8328.28014 - WebSocket Authorization Bypass
CVE-2026-2470
MEDIUM
Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'
CVSS 4.3
CVE-2026-54398
MEDIUM
MISP object edit authorization bypass allows unauthorized sharing group assignment
CVE-2026-53835
MEDIUM
OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent Bindings
CVSS 4.3
CVE-2026-53834
HIGH
OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands
CVSS 7.5
CVE-2026-53828
HIGH
OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement
CVSS 8.8
Details
Vulnerabilities
3,363
Exploit Likelihood
High