The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
2,832 vulnerabilities with CWE-863
CVE-2026-41348
MEDIUM
OpenClaw < 2026.3.31 - Group DM Channel Allowlist Bypass via Discord Slash Commands
CVSS 5.4
CVE-2026-41344
MEDIUM
OpenClaw < 2026.3.28 - Privilege Escalation via chat.send /verbose Parameter
CVSS 5.4
CVE-2026-41909
MEDIUM
OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing Actions
CVSS 5.4
CVE-2026-41908
MEDIUM
OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route
CVSS 4.3
CVE-2026-41233
MEDIUM
Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()
CVSS 5.4
CVE-2026-41232
MEDIUM
Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email Spoofing
CVSS 5.0
CVE-2026-5377
MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-35370
MEDIUM
uutils coreutils id Incorrect Access-Control Decisions via Misrepresented Group Membership
CVSS 4.4
CVE-2026-41131
MEDIUM
OpenFGA has Improper Policy Enforcement
CVSS 5.0
CVE-2026-40599
HIGH
ClearanceKit: Ad-hoc signed binaries can spoof Apple process identities in the global allowlist
CVSS 7.1
CVE-2026-41191
HIGH
FreeScout's signature only mailbox permission allows unauthorized mailbox chat setting changes
CVSS 7.1
CVE-2026-41190
HIGH
FreeScout has assigned-only visibility bypass via save_draft that allows hidden conversation draft injection
CVSS 7.1
CVE-2026-41189
HIGH
FreeScout has assigned-only visibility bypass that allows editing hidden customer-authored threads
CVSS 7.1
CVE-2026-40574
MEDIUM
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
CVSS 6.8
CVE-2026-29179
LOW
October: Editor Sub-Permission Bypass for Asset and Blueprint File Operations
CVSS 3.3
CVE-2026-26274
MEDIUM
October: Safe Mode Bypass via Twig Database Write Operations
CVSS 6.6
CVE-2026-26067
MEDIUM
October: Safe Mode Bypass via CSS Preprocessor Compilers
CVSS 4.9
CVE-2026-24176
MEDIUM
NVIDIA KAI Scheduler <0.13.0 - Auth Bypass
CVSS 4.3
CVE-2026-41303
HIGH
OpenClaw < 2026.3.28 - Authorization Bypass in Discord Text Approval Commands
CVSS 8.8
CVE-2026-34082
MEDIUM
Dify has IDOR in deleting someone else's chat conversation
CVSS 4.3
CVE-2026-33031
HIGH
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens
CVSS 8.1
CVE-2026-32228
HIGH
Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to
CVSS 7.5
CVE-2026-40350
HIGH
Movary User Management (/settings/users) has Authorization Bypass that Allows Low-Privileged Users to Enumerate All Users and Create Administrator Accounts
CVSS 8.8
CVE-2026-40304
MEDIUM
zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records
CVSS 5.3
CVE-2026-40155
MEDIUM
Auth0 Next.js SDK has Improper Proxy Cache Lookup
CVSS 5.4
Details
Vulnerabilities
2,832
Exploit Likelihood
High