The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,041 vulnerabilities with CWE-863
CVE-2026-11577
HIGH
Keycloak: keycloak: privilege escalation via partialimport fgap permission bypass
CVSS 7.2
CVE-2026-21031
HIGH
Samsung Mobile Devices - Improper Authorization in AppBlock
CVSS 7.8
CVE-2026-42547
MEDIUM
IRIS Alerts Can be Falsely Attributed to Customers
CVSS 5.4
CVE-2026-41235
HIGH
Froxlor 2.3.6 FTP Shell Assignment - Authorization Bypass
CVE-2026-50266
LOW
Openstack Neutron - Incorrect Authorization
CVSS 2.2
CVE-2026-10815
MEDIUM
LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
CVSS 6.3
CVE-2026-10860
MEDIUM
MISP CRUDComponent delete validation bypass via operator precedence error
CVSS 6.5
CVE-2026-41283
CRITICAL
Openstack Mistral - Incorrect Authorization
CVSS 9.9
CVE-2026-44654
HIGH
LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents
CVSS 8.1
CVE-2026-35482
HIGH
alf.io <2.0-M5-2606 Extension Scripts - Sandbox Escape
CVSS 8.0
CVE-2026-10616
MEDIUM
nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTasksTool.executeComplete authorization
CVSS 4.3
CVE-2026-3514
HIGH
Authentication Bypass in prefecthq/prefect
CVSS 7.5
CVE-2026-9048
MEDIUM
Slider Revolution 7.0.0-7.0.14 - Authenticated Sensitive Information Exposure via slider.get.full AJAX Action
CVSS 4.3
CVE-2026-22872
CRITICAL
Capsule < 0.13.0 - Authenticated Privilege Escalation via TenantResource RawItems Processing
CVSS 9.1
CVE-2026-45426
LOW
Apache Airflow Log Server - JWT Authorization Bypass
CVSS 3.1
CVE-2026-10211
MEDIUM
AstrBotDevs AstrBot fs.py _normalize_rw_path authorization
CVSS 6.3
CVE-2026-49376
MEDIUM
Jetbrains TeamCity < 2026.1 - Incorrect Authorization
CVSS 6.5
CVE-2026-49369
MEDIUM
Jetbrains YouTrack < 2026.1.13162 - Incorrect Authorization
CVSS 4.3
CVE-2026-48501
HIGH
GitHub CLI tokens leak via `gh attestation` commands
CVSS 7.4
CVE-2026-35674
HIGH
OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
CVSS 8.8
CVE-2026-35673
MEDIUM
OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes
CVSS 6.5
CVE-2026-34507
MEDIUM
OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
CVSS 5.4
CVE-2026-32906
MEDIUM
OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate
CVSS 4.3
CVE-2026-9808
HIGH
Mautic 7 - Authenticated Authorization Bypass in API v2 Endpoints
CVSS 7.1
CVE-2026-49299
MEDIUM
Openstack Neutron - Incorrect Authorization
Details
Vulnerabilities
3,041
Exploit Likelihood
High