The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
2,832 vulnerabilities with CWE-863
CVE-2026-4363
LOW
Incorrect Authorization in GitLab
CVSS 3.7
CVE-2026-28864
LOW
Apple Ios And Ipados < 18.7.7 - Denial of Service
CVSS 3.3
CVE-2026-33330
HIGH
FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callback
CVSS 7.1
CVE-2026-33326
MEDIUM
@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany
CVSS 4.3
CVE-2026-33527
MEDIUM
Parse Server: Session update endpoint allows overwriting server-generated session fields
CVSS 4.3
CVE-2026-33421
MEDIUM
Parse Server: LiveQuery bypasses CLP pointer permission enforcement
CVSS 6.5
CVE-2026-33676
MEDIUM
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read
CVSS 6.5
CVE-2026-33668
HIGH
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
CVSS 8.1
CVE-2026-33316
HIGH
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
CVSS 8.1
CVE-2026-28755
MEDIUM
NGINX ngx_stream_ssl_module vulnerability
CVSS 5.4
CVE-2026-32642
MEDIUM
Apache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permission
CVSS 4.3
CVE-2026-4639
HIGH
Galaxy Software Services|Vitals ESP - Incorrect Authorization
CVSS 8.8
CVE-2026-27646
MEDIUM
OpenClaw <2026.3.7 - Sandbox Escape
CVSS 6.1
CVE-2026-27183
MEDIUM
OpenClaw < 2026.3.7 - Shell Approval Gating Bypass via Dispatch Wrapper Depth Mismatch
CVSS 5.3
CVE-2026-33650
HIGH
AVideo's Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion
CVSS 7.6
CVE-2026-32899
MEDIUM
OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers
CVSS 4.3
CVE-2026-32895
MEDIUM
OpenClaw < 2026.2.26 - Sender Authorization Bypass in Slack System Event Handlers
CVSS 5.4
CVE-2026-32067
LOW
OpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing Store
CVSS 3.7
CVE-2026-32058
LOW
OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node
CVSS 2.6
CVE-2026-32051
HIGH
OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool Access
CVSS 8.8
CVE-2026-32050
LOW
OpenClaw < 2026.2.25 - Unauthorized Reaction Status Event Enqueue via Access Check Bypass
CVSS 3.7
CVE-2026-32042
HIGH
OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication
CVSS 8.8
CVE-2026-33428
MEDIUM
Discourse Allows Unauthorized Access to Deleted Posts Index via Group Membership
CVSS 6.5
CVE-2026-33424
MEDIUM
PM access granted through invites after access revocation
CVSS 5.9
CVE-2026-33291
MEDIUM
Discourse user can create Zendesk tickets even when it does not have access to topic
CVSS 5.4
Details
Vulnerabilities
2,832
Exploit Likelihood
High