The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,363 vulnerabilities with CWE-863
CVE-2026-45339
MEDIUM
Open WebUI: API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
CVSS 6.5
CVE-2026-44564
MEDIUM
Open WebUI: Read-Only Users Can Modify Collaborative Documents via Socket.IO
CVSS 5.4
CVE-2026-44561
MEDIUM
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
CVSS 5.4
CVE-2026-44557
MEDIUM
Open WebUI: Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
CVSS 4.3
CVE-2026-46366
HIGH
phpMyFAQ - Unauthenticated Information Disclosure via getIdFromSolutionId Permission Bypass
CVSS 7.5
CVE-2026-46362
MEDIUM
phpMyFAQ - Authorization Bypass in Admin Pages via Non-Terminating Permission Check
CVSS 6.5
CVE-2026-45009
MEDIUM
phpMyFAQ - Insufficient Authorization Check in Admin API Endpoints
CVSS 4.3
CVE-2026-45148
MEDIUM
SiYuan: Broken access control in SiYuan publish-mode Readers can enumerate metadata
CVSS 4.3
CVE-2026-44633
HIGH
Live Helper Chat: REST API chat update accepts arbitrary chat fields across department boundaries
CVSS 8.1
CVE-2026-44283
NONE
etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks
CVE-2026-42572
MEDIUM
Hatchet: Cross-tenant information disclosure in `listTasksByDAGIds`
CVSS 5.3
CVE-2026-41888
MEDIUM
Distribution: Tag deletion bypasses `storage.delete.enabled` configuration
CVSS 6.5
CVE-2026-44374
MEDIUM
Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
CVSS 4.3
CVE-2026-32991
HIGH
cPanel 11.110.0.0-11.136.0.9 - Incorrect Authorization
CVSS 7.1
CVE-2026-44380
HIGH
MISP: Improper access control in auth key reset allows privilege escalation to site administrator
CVSS 7.2
CVE-2026-42032
CRITICAL
CKAN: Unauthenticated Authorization Bypass in `datastore_search_sql`
CVSS 9.1
CVE-2026-43999
CRITICAL
vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escape
CVSS 9.9
CVE-2026-44573
HIGH
Next.js: Middleware / Proxy bypass in Pages Router applications using i18n
CVSS 7.5
CVE-2026-41050
CRITICAL
Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
CVSS 9.9
CVE-2026-2725
MEDIUM
Improper Authorization in Gerrit allowing Code Review Bypass via "Submitted Together"
CVSS 5.3
CVE-2026-45226
HIGH
Heym < 0.0.21 Authorization Bypass in Workflow Execution
CVSS 7.1
CVE-2026-44260
HIGH
efw4.X: readonly Flag Not Enforced Server-Side
CVSS 8.1
CVE-2026-43948
CRITICAL
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
CVSS 9.9
CVE-2026-35555
MEDIUM
Subnet Solutions PowerSYSTEM Center Incorrect Authorization
CVSS 6.3
CVE-2026-33570
MEDIUM
Subnet Solutions PowerSYSTEM Center Incorrect Authorization
CVSS 5.7
Details
Vulnerabilities
3,363
Exploit Likelihood
High