The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,360 vulnerabilities with CWE-863
CVE-2026-63738
MEDIUM
SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal
CVSS 4.3
CVE-2026-63733
MEDIUM
SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause
CVSS 4.3
CVE-2026-10755
LOW
All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration
CVSS 2.7
CVE-2026-16215
MEDIUM
geex-arts django-jet OAuth Credential Revoke authorization
CVSS 6.5
CVE-2026-16200
HIGH
zevorn rt-claw RPC swarm.c claw_tool_invoke authorization
CVSS 7.3
CVE-2026-16197
MEDIUM
Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization
CVSS 6.3
CVE-2026-16195
MEDIUM
Sipeed PicoClaw Group Message wecom.go dispatchIncoming authorization
CVSS 6.3
CVE-2026-10130
HIGH
QueryWeaver Authentication Bypass via Email Signup Token Issuance for Existing Accounts
CVSS 8.2
CVE-2026-16126
HIGH
zevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorization
CVSS 7.3
CVE-2026-16123
MEDIUM
nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization
CVSS 6.3
CVE-2026-16122
MEDIUM
nextlevelbuilder GoClaw exec_approval.go matchesAllowlist authorization
CVSS 4.3
CVE-2026-16119
MEDIUM
nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization
CVSS 6.3
CVE-2026-47866
HIGH
VMware Avi Load Balancer Authorization Bypass Vulnerability
CVSS 8.3
CVE-2026-55518
CRITICAL
Avo < 3.32.1 and 4.0.0-beta.51 - Association Authorization Bypass
CVSS 9.6
CVE-2026-54244
LOW
Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors
CVSS 3.5
CVE-2026-4938
MEDIUM
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
CVSS 6.5
CVE-2026-63309
MEDIUM
SurrealDB < 3.1.5 Information Disclosure via ORDER BY
CVSS 4.3
CVE-2026-63097
MEDIUM
Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure
CVSS 4.3
CVE-2026-14871
HIGH
osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
CVE-2026-16017
MEDIUM
mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
CVSS 6.3
CVE-2026-62231
HIGH
Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator
CVSS 8.1
CVE-2026-62228
HIGH
OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals
CVSS 8.8
CVE-2026-62225
MEDIUM
OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch
CVSS 5.4
CVE-2026-62224
MEDIUM
OpenClaw MS Teams < 2026.5.12 Authorization Bypass
CVSS 5.4
CVE-2026-62223
HIGH
OpenClaw < 2026.5.18 Authorization Bypass via Device-pair
CVSS 8.8
Details
Vulnerabilities
3,360
Exploit Likelihood
High