The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,363 vulnerabilities with CWE-863
CVE-2026-6290
HIGH
Velociraptor Query() Plugin Misapplies Permissions To Orgs
CVSS 8.0
CVE-2026-40291
HIGH
Chamilo LMS has Privilege Escalation via API User Role Modification
CVSS 8.8
CVE-2026-24069
MEDIUM
Improper Enforcement of Disabled Accounts in WebUI SSO in Kiuwan SAST
CVSS 5.4
CVE-2026-40191
MEDIUM
ClearanceKit Endpoint Security Events - Policy Bypass
CVE-2026-35657
MEDIUM
OpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History Route
CVSS 6.5
CVE-2026-35653
HIGH
OpenClaw < 2026.3.24 - Incorrect Authorization in POST /reset-profile via browser.request
CVSS 8.1
CVE-2026-35619
MEDIUM
OpenClaw < 2026.3.24 - Authorization Bypass via HTTP /v1/models Endpoint
CVSS 4.3
CVE-2026-35596
MEDIUM
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
CVSS 4.3
CVE-2026-40224
MEDIUM
systemd 259-259.2 - Local Privilege Escalation via Varlink Root Namespace Access
CVSS 6.7
CVE-2026-33551
LOW
OpenStack Keystone <26.1.1 - Privilege Escalation
CVSS 3.5
CVE-2026-2712
MEDIUM
WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation
CVSS 5.4
CVE-2026-35645
HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession
CVSS 8.1
CVE-2026-35635
MEDIUM
OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
CVSS 4.8
CVE-2026-34512
HIGH
OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint
CVSS 8.1
CVE-2026-40071
MEDIUM
pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions
CVSS 5.4
CVE-2026-39957
MEDIUM
Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users
CVSS 4.3
CVE-2026-2619
MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-1752
MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-33461
HIGH
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
CVSS 7.7
CVE-2026-33460
MEDIUM
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
CVSS 4.3
CVE-2026-27140
HIGH
Go cmd/go < 1.25.9 and < 1.26.2 - SWIG Build-Time Code Execution
CVSS 8.8
CVE-2026-39381
MEDIUM
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
CVSS 4.3
CVE-2026-39331
HIGH
ChurchCRM <7.1.0 Family API - Authorization Bypass
CVSS 8.1
CVE-2026-22682
HIGH
OpenHarness Improper Access Control via File Tools
CVSS 7.1
CVE-2026-35604
HIGH
File Browser share links remain accessible after Share/Download permissions are revoked
CVSS 8.1
Details
Vulnerabilities
3,363
Exploit Likelihood
High