The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,362 vulnerabilities with CWE-863
CVE-2026-55462
MEDIUM
Snipe-IT: Authorization bypass on print inventory page
CVSS 4.3
CVE-2026-55472
MEDIUM
Snipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
CVSS 4.3
CVE-2026-55460
HIGH
Snipe-IT: Authorization bypass on bulk editing users
CVSS 7.1
CVE-2026-55672
HIGH
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
CVSS 7.4
CVE-2026-59154
MEDIUM
Wekan: Checklist direct DDP updates can write checklist data into private boards
CVSS 4.3
CVE-2026-55638
HIGH
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
CVSS 8.6
CVE-2026-39903
HIGH
SimpleMachines - Simple Machines Forum Authorization Bypass via AttachmentApprove.php
CVSS 7.1
CVE-2026-22659
HIGH
FlaskBB Authorization Bypass via Topic ID Manipulation
CVSS 8.1
CVE-2026-40452
HIGH
Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users
CVSS 7.5
CVE-2026-15332
MEDIUM
zhayujie CowAgent Message Endpoint channel.py authorization
CVSS 6.3
CVE-2026-15286
MEDIUM
Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication
CVSS 4.3
CVE-2026-5069
MEDIUM
Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id'
CVSS 5.4
CVE-2026-15320
MEDIUM
Sipeed PicoClaw pico.go rt.ReloadConfig authorization
CVSS 5.4
CVE-2026-15318
MEDIUM
Sipeed PicoClaw MQTT Channel mqtt.go authorization
CVSS 6.3
CVE-2026-59227
MEDIUM
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVSS 4.3
CVE-2026-59226
LOW
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVSS 3.1
CVE-2026-59217
MEDIUM
Open WebUI < 0.10.0 - Knowledge Base Write-Access Bypass
CVSS 4.3
CVE-2026-59212
MEDIUM
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
CVSS 5.4
CVE-2026-61474
MEDIUM
MISP: Improper sharing group authorization check when adding attributes
CVE-2026-15125
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-6352
LOW
Incorrect Authorization in GitLab
CVSS 2.7
CVE-2026-58494
MEDIUM
Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
CVSS 6.5
CVE-2026-58211
MEDIUM
NATS Server: `no_auth_user` pre-CONNECT fast path bypasses user connection restrictions
CVSS 5.4
CVE-2026-35211
MEDIUM
OpenCTI < 7.260401.0 - Authenticated Painless Script Denial of Service
CVSS 6.5
CVE-2026-35210
HIGH
OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
CVSS 7.1
Details
Vulnerabilities
3,362
Exploit Likelihood
High