Search Results (14443 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106461 1 Backstage 2 Backstage, Plugin-scaffolder-backend 2026-10-07 4.3 Medium
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorrect authorization in scaffolder task listing. An authenticated internal user may be able to view metadata for scaffolder tasks outside the visibility intended by a deployment's permission policy. Stored task secrets are not included in the affected response, and no integrity or availability impact was identified. This issue is fixed in version 4.1.0.
CVE-2026-105268 1 Gitea 1 Gitea 2026-10-07 4.3 Medium
The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also accepted attachments that belong to comments on the issue. Because the author of an issue may edit and delete the issue's attachments, a user who opened an issue could rename or delete attachments that other users had posted in comments on that issue. The contents of the attachments could not be changed.
CVE-2026-103620 1 Github 1 Enterprise Server 2026-10-07 N/A
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository collaborator with write access to delete the current default branch through the GraphQL API and cause an attacker-controlled branch to become the new default. In repositories that required pull-request review but did not restrict branch deletion, this bypassed the review requirement and caused fresh clones and default-branch API requests to use attacker-controlled content. This vulnerability affected supported GitHub Enterprise Server releases in the 3.18, 3.19, 3.20, 3.21, and 3.22 series and was fixed in versions 3.18.16, 3.19.13, 3.20.9, 3.21.7, and 3.22.2. This vulnerability was reported via the GitHub Bug Bounty program.
CVE-2026-91181 1 Mattermost 2 Mattermost, Mattermost Server 2026-10-07 6.5 Medium
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email, and use it to join the team without authorization, via GET /api/v4/data_retention/policies/{policy_id}/teams.. Mattermost Advisory ID: MMSA-2026-00702
CVE-2026-82358 1 Rt-labs Ab 1 C-open 2026-10-07 6.5 Medium
RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.
CVE-2025-69016 2 Averta, Wordpress 2 Shortcodes And Extra Features For Phlox Theme, Wordpress 2026-10-07 4.3 Medium
Missing Authorization vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.22.
CVE-2026-14259 1 Mattermost 2 Mattermost, Mattermost Server 2026-10-07 4.3 Medium
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards despite administrator restrictions via importing a crafted .boardarchive file. Mattermost Advisory ID: MMSA-2026-00712
CVE-2026-14344 1 Mattermost 2 Mattermost, Mattermost Server 2026-10-07 4.3 Medium
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-and-blocks, and archive-import endpoints.. Mattermost Advisory ID: MMSA-2026-00715
CVE-2026-18132 2 Ibm, Redhat 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift 2026-10-07 6.5 Medium
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.
CVE-2026-8821 1 Mattermost 2 Mattermost, Mattermost Server 2026-10-07 7.1 High
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a restricted channel via the run owner field.. Mattermost Advisory ID: MMSA-2026-00677
CVE-2026-81164 2 Drupal, Entity Pdf Project 2 Entity Pdf, Entity Pdf 2026-10-07 5.4 Medium
Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.
CVE-2026-96589 1 Gitea 1 Gitea 2026-10-07 4.3 Medium
When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named recipient kept persistent read access to the private repository, including its code, issues, pull requests and wiki, and could clone it. The repository owner was not notified. Transfer-granted access is now removed while collaborations that existed before the transfer are preserved.
CVE-2026-79960 1 Gitea 1 Gitea 2026-10-07 7.1 High
When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in the push hook pipeline evaluated the owner instead of the deploy key. A holder of a writable deploy key could create protected tags without being on the tag allow list and change repository visibility through push options, for example making a private repository public. Pull requests created through the AGit flow with a deploy key were also attributed to the owner.
CVE-2026-105139 1 Obot-platform 1 Obot 2026-10-07 4.3 Medium
Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.
CVE-2026-102139 2 Accellion, Kiteworks 2 Kiteworks, Kiteworks Email Protection Gateway 2026-10-07 6.5 Medium
An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.
CVE-2026-39730 2026-10-07 7.1 High
Missing Authorization vulnerability in Marcin Wise Chat wise-chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wise Chat: from n/a through 3.4.3.
CVE-2026-102122 2 Accellion, Kiteworks 2 Kiteworks, Core 2026-10-07 4.3 Medium
Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder.
CVE-2026-106260 1 Google 1 Chrome 2026-10-07 4.3 Medium
Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106264 1 Google 1 Chrome 2026-10-07 5.4 Medium
Missing authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106241 1 Google 2 Android, Chrome 2026-10-07 9.6 Critical
Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)