The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
2,832 vulnerabilities with CWE-863
CVE-2026-33460
MEDIUM
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
CVSS 4.3
CVE-2026-27140
HIGH
Code execution vulnerability in SWIG code generation in cmd/go
CVSS 8.8
CVE-2026-39381
MEDIUM
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
CVSS 4.3
CVE-2026-39331
HIGH
ChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spam Arbitrary Families
CVSS 8.1
CVE-2026-22682
HIGH
OpenHarness Improper Access Control via File Tools
CVSS 7.1
CVE-2026-35604
HIGH
File Browser share links remain accessible after Share/Download permissions are revoked
CVSS 8.1
CVE-2026-35586
MEDIUM
Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng
CVSS 6.8
CVE-2026-35491
MEDIUM
Pi-hole FTL: CLI API sessions can import Teleporter archives and modify configuration
CVSS 6.1
CVE-2026-35490
CRITICAL
changedetection.io has an Authentication Bypass via Decorator Ordering
CVSS 9.8
CVE-2026-5384
MEDIUM
runZero Platform incorrect credential scope
CVSS 5.8
CVE-2026-5383
MEDIUM
runZero Explorer missing authorization check
CVSS 4.4
CVE-2026-5382
LOW
runZero Platform MCP endpoint information leak
CVSS 3.0
CVE-2026-5381
LOW
runZero Platform task information leak
CVSS 2.2
CVE-2026-5380
MEDIUM
runZero Platform cleartext secret exposure
CVSS 5.3
CVE-2026-5379
LOW
runZero Platform MCP certification information leak
CVSS 3.0
CVE-2026-5378
MEDIUM
runZero Platform user creation leak
CVSS 5.8
CVE-2026-5374
MEDIUM
runZero Platform MCP information leak
CVSS 5.8
CVE-2026-35464
HIGH
pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code execution
CVSS 7.5
CVE-2026-28808
CRITICAL
ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
CVSS 9.8
CVE-2026-35442
HIGH
Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries
CVSS 8.1
CVE-2026-35412
HIGH
Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwrite
CVSS 7.1
CVE-2026-34972
MEDIUM
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
CVSS 5.0
CVE-2026-35029
HIGH
LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint
CVSS 8.8
CVE-2026-5574
MEDIUM
Technostrobe HI-LED-WR120-G2 FsBrowseClean deletefile authorization
CVSS 6.5
CVE-2026-34953
CRITICAL
PraisonAI: Authentication Bypass in OAuthManager.validate_token()
CVSS 9.1
Details
Vulnerabilities
2,832
Exploit Likelihood
High