The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
2,832 vulnerabilities with CWE-863
CVE-2026-33251
MEDIUM
Discourse has a Hidden Solved topics permission bypass
CVSS 5.4
CVE-2026-33312
MEDIUM
Read-only Vikunja users can delete project background images via broken object-level authorization
CVSS 5.4
CVE-2026-33132
MEDIUM
ZITADEL is missing enforcement of organization scopes
CVSS 5.3
CVE-2026-32947
MEDIUM
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)
CVSS 4.9
CVE-2026-32946
LOW
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
CVSS 2.7
CVE-2026-31805
MEDIUM
Discourse has a poll authorization bypass via post_id array parameter
CVSS 5.3
CVE-2026-32811
HIGH
Heimdall: Path received via Envoy gRPC corrupted when containing query string
CVSS 8.2
CVE-2026-32767
CRITICAL
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
CVSS 9.8
CVE-2026-32761
MEDIUM
File Browser has an Authorization Policy Bypass in its Public Share Download Flow
CVSS 6.5
CVE-2026-32758
MEDIUM
File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter
CVSS 6.5
CVE-2026-33410
MEDIUM
Discourse hardens chat DM channel creation and expansion
CVSS 5.4
CVE-2026-32035
MEDIUM
OpenClaw < 2026.3.2 - Missing Owner Flag Validation in Discord Voice Transcript Handler
CVSS 5.9
CVE-2026-32028
MEDIUM
OpenClaw < 2026.2.25 - Missing Authorization Check in Discord DM Reaction Ingress
CVSS 5.3
CVE-2026-32027
MEDIUM
OpenClaw < 2026.2.26 - Improper Authorization via DM Pairing Store Identity Inheritance in Group Allowlist
CVSS 6.5
CVE-2026-32023
HIGH
OpenClaw < 2026.2.24 - Approval Gating Bypass via Dispatch-Wrapper Depth-Cap Mismatch in system.run
CVSS 7.1
CVE-2026-32021
MEDIUM
OpenClaw < 2026.2.22 - Authorization Bypass via Display Name Collision in Feishu allowFrom
CVSS 6.5
CVE-2026-32006
LOW
OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Fallback in Group Allowlist
CVSS 3.1
CVE-2026-32005
MEDIUM
OpenClaw < 2026.2.25 - Authorization Bypass in Interactive Callbacks via Sender Check Skip
CVSS 6.8
CVE-2026-32001
MEDIUM
OpenClaw < 2026.2.22 - Node Role Device-Identity Bypass via WebSocket Authentication
CVSS 5.4
CVE-2026-28282
LOW
Discourse vulnerable to group membership addition permission bypass via discourse-policy plugin
CVE-2026-27936
MEDIUM
Discourse discloses restricted post-action counts to non-privileged users
CVE-2026-33302
HIGH
OpenEMR: zhAclCheck Ignores Explicit ACL Denies
CVSS 8.1
CVE-2026-31998
HIGH
OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds
CVSS 8.6
CVE-2026-31991
LOW
OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group Allowlist
CVSS 3.7
CVE-2026-32693
HIGH
Unauthorized access to Kubernetes secrets in Juju
CVSS 8.8
Details
Vulnerabilities
2,832
Exploit Likelihood
High