Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

9,119 CVEs tagged with CWE-862479 Critical, 2,091 High, 6,248 Medium, 300 Low, 1 Unrated.

CVE-2026-16544

Published Jul 22, 2026

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workf…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-63262

Published Jul 22, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-63143

Published Jul 21, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workfl…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-63141

Published Jul 21, 2026

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privilege…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-61267

Published Jul 21, 2026

Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65055

Published Jul 21, 2026

Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any pri…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-63092

Published Jul 21, 2026

kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintex…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-47688

Published Jul 21, 2026

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47657

Published Jul 21, 2026

HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenti…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-47416

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspace…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-47413

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-47412

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-47411

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings ta…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47409

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /work…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-47405

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authentica…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-16454

Published Jul 21, 2026

In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. Thi…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-47394

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named four vuln…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-28310

Published Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-28309

Published Jul 21, 2026

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows d…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-65050

Published Jul 21, 2026

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block…

CVSS 7.1 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-11876

Published Jul 21, 2026

In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-6792

Published Jul 21, 2026

Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65007

Published Jul 21, 2026

The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Showing 451-475 of 9,119 CVEsPage 19 of 365