The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,041 vulnerabilities with CWE-863
CVE-2026-6341
MEDIUM
Mattermost Plugins - Incorrect Authorization via Direct API Requests
CVSS 4.3
CVE-2026-4273
LOW
Insufficient token rotation validation in remote cluster invite confirmation
CVSS 3.7
CVE-2026-28759
MEDIUM
Mattermost Shared Channel Sync - Unauthorized Member Removal
CVSS 4.3
CVE-2026-45316
LOW
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
CVSS 3.5
CVE-2026-44567
HIGH
Open WebUI: Open WebUI Improper Authorization Control
CVSS 7.3
CVE-2026-45672
HIGH
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
CVSS 8.8
CVE-2026-45339
MEDIUM
Open WebUI: API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
CVSS 6.5
CVE-2026-44564
MEDIUM
Open WebUI: Read-Only Users Can Modify Collaborative Documents via Socket.IO
CVSS 5.4
CVE-2026-44561
MEDIUM
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
CVSS 5.4
CVE-2026-44557
MEDIUM
Open WebUI: Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
CVSS 4.3
CVE-2026-46366
HIGH
phpMyFAQ - Unauthenticated Information Disclosure via getIdFromSolutionId Permission Bypass
CVSS 7.5
CVE-2026-46362
MEDIUM
phpMyFAQ - Authorization Bypass in Admin Pages via Non-Terminating Permission Check
CVSS 6.5
CVE-2026-45009
MEDIUM
phpMyFAQ - Insufficient Authorization Check in Admin API Endpoints
CVSS 4.3
CVE-2026-45148
MEDIUM
SiYuan: Broken access control in SiYuan publish-mode Readers can enumerate metadata
CVSS 4.3
CVE-2026-44633
HIGH
Live Helper Chat: REST API chat update accepts arbitrary chat fields across department boundaries
CVSS 8.1
CVE-2026-44283
NONE
etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks
CVE-2026-42572
MEDIUM
Hatchet: Cross-tenant information disclosure in `listTasksByDAGIds`
CVSS 5.3
CVE-2026-41888
MEDIUM
Distribution: Tag deletion bypasses `storage.delete.enabled` configuration
CVSS 6.5
CVE-2026-44374
MEDIUM
Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
CVSS 4.3
CVE-2026-32991
HIGH
cPanel 11.110.0.0-11.136.0.9 - Incorrect Authorization
CVSS 7.1
CVE-2026-44380
HIGH
MISP: Improper access control in auth key reset allows privilege escalation to site administrator
CVSS 7.2
CVE-2026-42032
CRITICAL
CKAN: Unauthenticated Authorization Bypass in `datastore_search_sql`
CVSS 9.1
CVE-2026-43999
CRITICAL
vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escape
CVSS 9.9
CVE-2026-44573
HIGH
Next.js: Middleware / Proxy bypass in Pages Router applications using i18n
CVSS 7.5
CVE-2026-41050
CRITICAL
Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
CVSS 9.9
Details
Vulnerabilities
3,041
Exploit Likelihood
High