Vulnerabilities (CVE)

Filtered by CWE-862
Total 9866 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-84470 2026-09-04 N/A 6.4 MEDIUM
A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A principal that holds read (but not use) permission on an instance group -- for example the built-in read-only System Auditor role -- together with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use, bypassing execution-placement isolation.
CVE-2026-32480 2026-09-04 N/A 5.3 MEDIUM
Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11.
CVE-2026-27347 2026-09-04 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2.
CVE-2026-85605 2026-09-04 N/A 5.3 MEDIUM
Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks.
CVE-2026-85512 2026-09-04 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-85306 2026-09-04 N/A 6.5 MEDIUM
Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5.
CVE-2026-84754 2026-09-04 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
CVE-2026-71962 1 Flowiseai 1 Flowise 2026-09-04 N/A 7.5 HIGH
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication whitelist, which bypasses all session and API key verification. Attackers can supply valid chatflowId, chatId, and fileName identifiers to retrieve files from any chatflow on the instance, including private chatflows belonging to other workspaces or organizations.
CVE-2026-20696 1 Apple 1 Macos 2026-09-04 N/A 5.5 MEDIUM
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.4. An app may be able to access sensitive user data.
CVE-2026-84794 2026-09-04 N/A 7.1 HIGH
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
CVE-2026-72681 1 Elastic 1 Kibana 2026-09-03 N/A 6.5 MEDIUM
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.
CVE-2026-85304 2026-09-03 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.
CVE-2026-84779 2026-09-03 N/A 8.1 HIGH
Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions.
CVE-2026-84757 2026-09-03 N/A 8.2 HIGH
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
CVE-2026-84755 2026-09-03 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
CVE-2026-84215 2026-09-03 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
CVE-2026-17563 2026-09-03 N/A 5.3 MEDIUM
The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
CVE-2026-81427 2026-09-03 N/A 4.3 MEDIUM
The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.
CVE-2026-77787 2026-09-03 N/A 2.7 LOW
The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users.
CVE-2025-15485 2026-09-03 N/A 8.2 HIGH
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc