The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,359 vulnerabilities with CWE-863
CVE-2026-7868
MEDIUM
This Power System update is being released to address incorrect authorization
CVSS 6.5
CVE-2026-14167
HIGH
ads-tec Industrial IT: Privilege escalation during configuration import
CVSS 8.8
CVE-2026-43672
HIGH
macOS < 14.8.8, < 15.7.8, < 26.6 - Privacy Preferences Bypass
CVSS 7.1
CVE-2026-42016
HIGH
Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
CVSS 8.1
CVE-2026-17568
HIGH
Devolutions Server - Incorrect Authorization
CVSS 8.8
CVE-2026-17530
MEDIUM
AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization
CVSS 6.3
CVE-2026-17529
MEDIUM
AstrBotDevs AstrBot astr_main_agent.py authorization
CVSS 6.3
CVE-2026-59689
HIGH
Progress LoadMaster Family - Authenticated Root Privilege Escalation
CVSS 8.0
CVE-2026-17039
LOW
Pki-core: dogtag-pki: redhat-pki: pki-core: ca renewal request processing omits realm authorization check performed by enrollment path
CVSS 3.1
CVE-2026-8789
HIGH
Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion
CVSS 8.1
CVE-2026-15704
CRITICAL
CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components
CVSS 9.8
CVE-2026-15630
CRITICAL
Casdoor < v3.115.0 - Authenticated Cross-Tenant Resource Manipulation via ID Parameter Mismatch
CVSS 9.9
CVE-2026-59678
HIGH
Linux-Gaming PortProtonQt - Unauthorized Mount and Network Changes
CVE-2026-13068
MEDIUM
MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse
CVSS 4.2
CVE-2026-13067
MEDIUM
tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket
CVSS 6.3
CVE-2026-13061
MEDIUM
Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage
CVSS 4.3
CVE-2026-13060
MEDIUM
$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access
CVSS 6.5
CVE-2026-65602
MEDIUM
Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass
CVE-2026-65601
MEDIUM
Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef
CVE-2026-65596
HIGH
n8n before 1.123.64 Credential Exfiltration via GraphQL Node
CVSS 8.1
CVE-2026-65594
MEDIUM
n8n before 2.30.1 Missing OAuth Authorization Check
CVSS 6.5
CVE-2026-65015
HIGH
n8n before 2.30.1 Privilege Escalation via run_node_tool
CVSS 8.8
CVE-2026-63145
MEDIUM
Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromise
CVSS 4.3
CVE-2026-63142
MEDIUM
Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
CVSS 5.0
CVE-2026-61325
HIGH
Oracle Advanced Benefits 12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
Details
Vulnerabilities
3,359
Exploit Likelihood
High