The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
2,832 vulnerabilities with CWE-863
CVE-2026-40515
HIGH
OpenHarness Permission Bypass via grep and glob root argument
CVSS 7.5
CVE-2026-24749
MEDIUM
Silverstripe Assets Module has a DBFile::getURL() permission bypass
CVSS 5.3
CVE-2026-39350
MEDIUM
Istio AuthorizationPolicy Incorrect Regex Matching of Dots in serviceAccounts Fields Allows Policy Bypass
CVSS 5.4
CVE-2026-33888
MEDIUM
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
CVSS 5.3
CVE-2026-6383
MEDIUM
Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation
CVSS 5.4
CVE-2026-4857
HIGH
SailPoint IdentityIQ Debug UI Incorrect Authorization
CVSS 8.4
CVE-2026-6290
HIGH
Velociraptor Query() Plugin Misapplies Permissions To Orgs
CVSS 8.0
CVE-2026-40291
HIGH
Chamilo LMS has Privilege Escalation via API User Role Modification
CVSS 8.8
CVE-2026-24069
MEDIUM
Improper Enforcement of Disabled Accounts in WebUI SSO in Kiuwan SAST
CVSS 5.4
CVE-2026-40191
MEDIUM
ClearanceKit has a policy bypass via dual-path Endpoint Security events checking only source path
CVE-2026-35657
MEDIUM
OpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History Route
CVSS 6.5
CVE-2026-35653
HIGH
OpenClaw < 2026.3.24 - Incorrect Authorization in POST /reset-profile via browser.request
CVSS 8.1
CVE-2026-35619
MEDIUM
OpenClaw < 2026.3.24 - Authorization Bypass via HTTP /v1/models Endpoint
CVSS 4.3
CVE-2026-35596
MEDIUM
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
CVSS 4.3
CVE-2026-40224
MEDIUM
Systemd < 260 - Privilege Escalation
CVSS 6.7
CVE-2026-33551
LOW
OpenStack Keystone <26.1.1 - Privilege Escalation
CVSS 3.5
CVE-2026-2712
MEDIUM
WP-Optimize <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update and Image Manipulation
CVSS 5.4
CVE-2026-35645
HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession
CVSS 8.1
CVE-2026-35635
MEDIUM
OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
CVSS 4.8
CVE-2026-34512
HIGH
OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint
CVSS 8.1
CVE-2026-40071
MEDIUM
pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions
CVSS 5.4
CVE-2026-39957
MEDIUM
Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users
CVSS 4.3
CVE-2026-2619
MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-1752
MEDIUM
Incorrect Authorization in GitLab
CVSS 4.3
CVE-2026-33461
HIGH
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
CVSS 7.7
Details
Vulnerabilities
2,832
Exploit Likelihood
High