The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,362 vulnerabilities with CWE-863
CVE-2026-14896
MEDIUM
Nomad vulnerable to cross-namespace host volume claim deletion
CVSS 4.2
CVE-2026-13151
LOW
Incorrect Authorization in GitLab
CVSS 2.7
CVE-2026-8800
LOW
Cross-Org External Token Metadata accessible to AuditUser role
CVSS 2.7
CVE-2026-58254
MEDIUM
NATS Server: Incomplete fix for CVE-2026-33249: Leaf node connections bypass Nats-Trace-Dest permission check
CVSS 6.5
CVE-2026-58214
MEDIUM
NATS Server: MQTT subscribe ACL bypass via $MQTT.deliver.pubrel prefix (incomplete fix for CVE-2026-33217)
CVSS 4.3
CVE-2026-58209
MEDIUM
NATS Server: MQTT retained and QoS replay bypass subscribe deny filters
CVSS 4.3
CVE-2026-55873
MEDIUM
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
CVSS 4.3
CVE-2026-54652
HIGH
Frigate viewer can read logs exposing admin and camera credentials
CVSS 8.1
CVE-2026-60125
MEDIUM
importModule function in MISP ignores per-organisation import module restrictions
CVE-2026-56778
MEDIUM
n8n - Authorization Bypass in Public API Execution Retry Endpoint
CVSS 6.4
CVE-2026-56776
HIGH
n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint
CVSS 7.4
CVE-2026-56775
MEDIUM
n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints
CVSS 5.4
CVE-2026-56220
MEDIUM
Capgo - Unauthorized Manifest Insertion via Read-Only Org Member
CVSS 6.5
CVE-2026-56086
HIGH
Dell PowerProtect Data Domain - Incorrect Authorization
CVSS 8.8
CVE-2026-55428
HIGH
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
CVSS 8.2
CVE-2026-54698
MEDIUM
Hasura: Row-level authorization bypass on table computed fields
CVE-2026-53935
MEDIUM
Cilium - Cross-Namespace Service Traffic Hijacking via addressMatcher
CVSS 6.9
CVE-2026-50529
HIGH
DataEase: Link Token Leakage Prior to Share Password/Ticket Validation
CVE-2026-55435
MEDIUM
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
CVSS 5.4
CVE-2026-12352
MEDIUM
Digi International PortServer TS 1/2/4 - Incorrect Authorization
CVSS 5.9
CVE-2026-34047
CRITICAL
Coolify: WebSocket Endpoint Access Control Flaw Leading to Remote Code Execution
CVSS 9.9
CVE-2026-53642
MEDIUM
FOSSBilling: Unverified clients can access client-area pages when email confirmation is required
CVE-2026-32718
MEDIUM
Coolify read-scoped API tokens can perform state-changing validation operations
CVSS 6.5
CVE-2026-54765
HIGH
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
CVSS 8.5
CVE-2026-42331
HIGH
FOSSBilling missing authorization in guest Invoice API endpoints
Details
Vulnerabilities
3,362
Exploit Likelihood
High