The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,363 vulnerabilities with CWE-863
CVE-2026-53521
MEDIUM
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
CVSS 6.4
CVE-2026-49397
MEDIUM
Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVSS 5.3
CVE-2026-47120
HIGH
Nezha Monitoring - AlertRule Cron Task Ownership Bypass
CVSS 7.1
CVE-2026-46717
HIGH
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
CVSS 7.7
CVE-2026-54397
MEDIUM
MISP event editing allows unauthorized assignment to undisclosed sharing groups
CVE-2026-54362
MEDIUM
MISP template builder exposes non-visible custom galaxies across organisations
CVE-2026-54358
HIGH
MISP organization administrators can target site administrator accounts for password reset
CVE-2026-54357
MEDIUM
MISP improper authorization allows organization administrators to modify site administrator user settings
CVE-2026-42604
MEDIUM
Actual has an OpenID `client_secret` Disclosure via Broken Authorization Guard in `/openid/config`
CVE-2026-50008
MEDIUM
Parse Server: Server option routeAllowList is bypassable through batch sub-requests
CVE-2026-47236
MEDIUM
Solidtime team page exposes pending invitation and member emails to employees who lack invitations:view/members:view permission
CVSS 4.3
CVE-2026-44173
MEDIUM
MariaDB: FILE privilege was not checked for subqueries in the FROM clause
CVSS 5.0
CVE-2026-44169
MEDIUM
MariaDB: Authorization bypass in role-based routine-level privilege check exposes stored routine definitions
CVSS 4.3
CVE-2026-7387
HIGH
Mattermost group syncable endpoints allow privilege escalation via scheme_admin
CVSS 8.8
CVE-2026-6739
MEDIUM
Mattermost: Delegated admins could patch protected default system roles
CVSS 6.7
CVE-2026-45831
HIGH
ChromaDB - Incorrect Authorization
CVSS 8.8
CVE-2026-53721
HIGH
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
CVSS 8.2
CVE-2026-47195
HIGH
Quest Bot: Per-channel permission overwrite bypass in purge and slowmode commands.
CVE-2026-47238
MEDIUM
ClipBucket: IDOR in videos subtitle editor
CVSS 6.5
CVE-2026-53809
LOW
OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy
CVSS 3.8
CVE-2026-53808
MEDIUM
OpenClaw < 2026.5.6 - Approval Policy Bypass in Skill Workshop Apply Flow
CVSS 6.5
CVE-2026-53807
HIGH
OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFrom
CVSS 8.8
CVE-2026-46519
HIGH
mcp-server-kubernetes Affected By Tool Access Control Bypass: Presentation-Layer Filtering Without Execution-Layer Enforcement
CVSS 8.8
CVE-2026-6277
MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-6269
MEDIUM
Incorrect Authorization in GitLab
CVSS 5.4
Details
Vulnerabilities
3,363
Exploit Likelihood
High