The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,360 vulnerabilities with CWE-863
CVE-2026-61325
HIGH
Oracle Advanced Benefits 12.2.15 - Authenticated Data Access and Modification via HTTP
CVSS 7.6
CVE-2026-60951
HIGH
Oracle Time and Labor 12.2.3-12.2.15 - Authenticated Data Creation, Deletion, and Unauthorized Access via HTTP
CVSS 8.1
CVE-2026-60663
CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 9.9
CVE-2026-60320
HIGH
Oracle Data Integrator 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Sensitive Data Exposure via HTTP
CVSS 7.5
CVE-2026-43947
HIGH
FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass
CVE-2026-43946
HIGH
FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue
CVE-2026-43945
HIGH
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
CVE-2026-65054
LOW
MediaCMS Private Media Metadata Disclosure via Playlist Ownership Loophole
CVSS 3.1
CVE-2026-47697
HIGH
Shelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit data
CVSS 7.1
CVE-2026-56146
MEDIUM
Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure
CVSS 5.4
CVE-2026-56144
MEDIUM
Incorrect Authorization in Elasticsearch Leading to Information Disclosure
CVSS 5.3
CVE-2026-49092
MEDIUM
Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure
CVSS 4.3
CVE-2026-47407
CRITICAL
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
CVE-2026-15829
HIGH
SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox
CVE-2026-65049
CRITICAL
Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action
CVSS 9.3
CVE-2026-59851
HIGH
Libssh: libssh: authentication bypass via missing gssapi principal check
CVSS 8.8
CVE-2026-47128
MEDIUM
nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`
CVSS 6.1
CVE-2026-64651
MEDIUM
AI SDK OpenCode Harness Tool Relay Authorization Bypass
CVE-2026-64650
MEDIUM
AI SDK Codex Harness Tool Relay Authorization Bypass
CVE-2026-44231
CRITICAL
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint
CVSS 9.1
CVE-2026-63755
MEDIUM
SurrealDB before 3.1.0 Permission Bypass via WHERE Clause
CVSS 6.5
CVE-2026-63751
MEDIUM
SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch
CVSS 4.3
CVE-2026-63749
MEDIUM
SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT
CVSS 4.3
CVE-2026-63742
MEDIUM
SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT
CVSS 4.3
CVE-2026-63740
MEDIUM
SurrealDB before 3.1.4 Array Element Permission Bypass
CVSS 6.5
Details
Vulnerabilities
3,360
Exploit Likelihood
High