The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
2,832 vulnerabilities with CWE-863
CVE-2026-27447
MEDIUM
OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup
CVSS 4.8
CVE-2026-33105
CRITICAL
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-32213
CRITICAL
Azure AI Foundry Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-32173
HIGH
Azure SRE Agent Information Disclosure Vulnerability
CVSS 8.6
CVE-2026-34376
HIGH
PdfDing: Password-protected share bypass via direct serve endpoint
CVSS 7.5
CVE-2026-34453
HIGH
SiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked content
CVSS 7.5
CVE-2026-34586
MEDIUM
PdfDing: Shared PDF Expiration, Max Views, and Deletion Bypass via Serve/Download Endpoints
CVSS 6.5
CVE-2026-32726
HIGH
SciTokens C++: Sibling-Path Authorization Bypass
CVSS 8.1
CVE-2026-34532
CRITICAL
Parse Server: Cloud function validator bypass via prototype chain traversal
CVSS 9.1
CVE-2026-33579
CRITICAL
OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval
CVSS 9.9
CVE-2026-33578
MEDIUM
OpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser Extensions
CVSS 4.3
CVE-2026-33577
HIGH
OpenClaw < 2026.3.28 - Insufficient Scope Validation in node.pair.approve
CVSS 8.1
CVE-2026-33576
MEDIUM
OpenClaw < 2026.3.28 - Unauthorized Media Download via Zalo Channel
CVSS 6.5
CVE-2026-34509
MEDIUM
OpenClaw < 2026.3.8 - Sender Allowlist Bypass in Microsoft Teams Plugin via Route Allowlist Configuration
CVSS 4.3
CVE-2026-34506
MEDIUM
OpenClaw < 2026.3.8 - Sender Allowlist Bypass in Microsoft Teams Plugin via Route Allowlist Configuration
CVSS 4.3
CVE-2026-24029
MEDIUM
DNS over HTTPS ACL bypass
CVSS 6.5
CVE-2026-0562
HIGH
Insecure Direct Object Reference (IDOR) in parisneo/lollms
CVSS 8.3
CVE-2026-32978
HIGH
OpenClaw < 2026.3.11 - Approval Bypass via Unrecognized Script Runners
CVSS 8.0
CVE-2026-32972
HIGH
OpenClaw < 2026.3.11 - Authorization Bypass in Browser Profile Management via browser.request
CVSS 7.1
CVE-2026-32924
CRITICAL
OpenClaw < 2026.3.12 - Authorization Bypass via Misclassified Reaction Events in Feishu
CVSS 9.8
CVE-2026-32923
MEDIUM
OpenClaw < 2026.3.11 - Authorization Bypass in Discord Guild Reaction Allowlist Enforcement
CVSS 5.4
CVE-2026-32919
MEDIUM
OpenClaw < 2026.3.11 - Unauthorized Session Reset via agent Slash Commands
CVSS 6.1
CVE-2026-32918
HIGH
OpenClaw < 2026.3.11 - Session Sandbox Escape via session_status Tool
CVSS 8.4
CVE-2026-32915
HIGH
OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Subagent Control Surface
CVSS 8.8
CVE-2026-32914
HIGH
OpenClaw < 2026.3.12 - Insufficient Access Control in /config and /debug Endpoints
CVSS 8.8
Details
Vulnerabilities
2,832
Exploit Likelihood
High