The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,363 vulnerabilities with CWE-863
CVE-2026-10860
MEDIUM
MISP CRUDComponent delete validation bypass via operator precedence error
CVSS 6.5
CVE-2026-41283
CRITICAL
Openstack Mistral - Incorrect Authorization
CVSS 9.9
CVE-2026-44654
HIGH
LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents
CVSS 8.1
CVE-2026-35482
HIGH
alf.io <2.0-M5-2606 Extension Scripts - Sandbox Escape
CVSS 8.0
CVE-2026-10616
MEDIUM
nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTasksTool.executeComplete authorization
CVSS 4.3
CVE-2026-3514
HIGH
Authentication Bypass in prefecthq/prefect
CVSS 7.5
CVE-2026-9048
MEDIUM
Slider Revolution 7.0.0-7.0.14 - Authenticated Sensitive Information Exposure via slider.get.full AJAX Action
CVSS 4.3
CVE-2026-22872
CRITICAL
Capsule < 0.13.0 - Authenticated Privilege Escalation via TenantResource RawItems Processing
CVSS 9.1
CVE-2026-45426
LOW
Apache Airflow Log Server - JWT Authorization Bypass
CVSS 3.1
CVE-2026-10211
MEDIUM
AstrBotDevs AstrBot fs.py _normalize_rw_path authorization
CVSS 6.3
CVE-2026-49376
MEDIUM
Jetbrains TeamCity < 2026.1 - Incorrect Authorization
CVSS 6.5
CVE-2026-49369
MEDIUM
Jetbrains YouTrack < 2026.1.13162 - Incorrect Authorization
CVSS 4.3
CVE-2026-48501
HIGH
GitHub CLI tokens leak via `gh attestation` commands
CVSS 7.4
CVE-2026-35674
HIGH
OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
CVSS 8.8
CVE-2026-35673
MEDIUM
OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes
CVSS 6.5
CVE-2026-34507
MEDIUM
OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
CVSS 5.4
CVE-2026-32906
MEDIUM
OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate
CVSS 4.3
CVE-2026-9808
HIGH
Mautic 7 - Authenticated Authorization Bypass in API v2 Endpoints
CVSS 7.1
CVE-2026-49299
MEDIUM
Openstack Neutron - Incorrect Authorization
CVE-2026-44882
HIGH
Portainer: Kubernetes middleware continues after token validation failure, bypassing endpoint authorization
CVSS 8.1
CVE-2026-44850
HIGH
Portainer: Bind-mount restriction bypass via HostConfig.Mounts
CVSS 8.5
CVE-2026-46823
HIGH
Oracle Public Sector Financials (International) 12.2.6-12.2.15 - Unauthorized Data Access via Authorization Component
CVSS 7.7
CVE-2026-42070
MEDIUM
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API
CVE-2026-45042
HIGH
RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source
CVE-2026-44394
MEDIUM
Openstack Keystone - Incorrect Authorization
CVSS 6.0
Details
Vulnerabilities
3,363
Exploit Likelihood
High