The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,360 vulnerabilities with CWE-863
CVE-2026-62221
MEDIUM
OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom
CVSS 5.4
CVE-2026-62219
HIGH
OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs
CVSS 7.1
CVE-2026-62217
HIGH
OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals
CVSS 8.8
CVE-2026-62209
HIGH
OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch
CVSS 8.1
CVE-2026-62202
HIGH
OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron
CVSS 8.8
CVE-2026-43977
HIGH
wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API
CVSS 7.5
CVE-2026-62290
HIGH
cert-manager 1.18.0-1.19.5, 1.20.0-1.20.2 - ACME Challenge Policy Bypass
CVSS 7.3
CVE-2026-47086
LOW
Cyrusimap Cyrus Imap < 3.12.3 - Incorrect Authorization
CVSS 3.5
CVE-2026-47084
MEDIUM
Cyrusimap Cyrus Imap < 3.12.3 - Incorrect Authorization
CVSS 6.5
CVE-2026-47082
MEDIUM
Cyrusimap Cyrus Imap < 3.12.3 - Incorrect Authorization
CVSS 5.4
CVE-2026-47081
LOW
Cyrusimap Cyrus Imap < 3.12.3 - Incorrect Authorization
CVSS 3.1
CVE-2026-63085
HIGH
Axelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational Record Persistence
CVSS 8.8
CVE-2026-55608
MEDIUM
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
CVSS 4.2
CVE-2026-56743
MEDIUM
Cilium 1.19.0-1.19.4 NetworkPolicy - Same-Namespace Ingress Bypass
CVSS 5.4
CVE-2026-61643
MEDIUM
FastGPT: workflow runtime can execute another user's private HTTP toolset
CVSS 5.9
CVE-2026-59258
HIGH
immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser
CVSS 8.3
CVE-2026-53515
HIGH
Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/sso
CVSS 7.1
CVE-2026-53512
CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVSS 9.1
CVE-2026-49997
MEDIUM
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
CVSS 5.4
CVE-2026-62683
LOW
File Browser: Trailing-slash delete leaves a stale public share behind
CVSS 3.1
CVE-2026-55242
HIGH
ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix
CVSS 8.8
CVE-2026-61644
HIGH
FastGPT >= 4.14.17, < 4.15.0-beta5 - Cross-Tenant Dataset Disclosure
CVSS 7.7
CVE-2026-54563
HIGH
Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`) — scoped DAV credential escapes its configured account root
CVSS 7.1
CVE-2026-54560
HIGH
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
CVSS 7.6
CVE-2026-60087
MEDIUM
PraisonAI before 1.6.78 Tool Approval Cache Bypass
CVSS 6.1
Details
Vulnerabilities
3,360
Exploit Likelihood
High