Search Results (13390 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-76560 1 Redhat 10 Directory Server, Directory Server E4s, Enterprise Linux and 7 more 2026-09-08 7.5 High
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
CVE-2026-7867 1 Redhat 2 Enterprise Linux, Enterprise Linux Eus 2026-09-08 7.8 High
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.
CVE-2026-81781 2026-09-08 7.1 High
Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.
CVE-2026-81790 2026-09-08 7.5 High
Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.
CVE-2026-76963 1 Sap Se 1 Sap Netweaver And Abap Platform 2026-09-08 4.3 Medium
Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.
CVE-2026-86544 1 Knowns-dev 1 Knowns 2026-09-08 8.1 High
knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.
CVE-2026-76962 2026-09-08 4.3 Medium
SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.
CVE-2026-86438 1 Laradashboard 1 Lara Dashboard 2026-09-07 7.2 High
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
CVE-2026-86437 1 Laradashboard 1 Lara Dashboard 2026-09-07 7.2 High
Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.
CVE-2026-86436 1 Laradashboard 1 Lara Dashboard 2026-09-07 5.4 Medium
Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits execution of the uploaded file type.
CVE-2026-86499 1 Jetbrains 1 Youtrack 2026-09-07 4.3 Medium
In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
CVE-2026-86332 2 Red Hat, Redhat 2 Red Hat Openshift Ai (rhoai), Openshift Ai 2026-09-07 6.5 Medium
A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).
CVE-2026-86493 1 Jetbrains 1 Youtrack 2026-09-07 6.5 Medium
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
CVE-2026-86494 1 Jetbrains 1 Youtrack 2026-09-07 7.7 High
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
CVE-2026-86495 1 Jetbrains 1 Youtrack 2026-09-07 6.5 Medium
In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
CVE-2026-86498 1 Jetbrains 1 Youtrack 2026-09-07 7.7 High
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
CVE-2026-86479 1 Jetbrains 1 Youtrack 2026-09-07 8 High
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
CVE-2026-86496 1 Jetbrains 1 Youtrack 2026-09-07 4.3 Medium
In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
CVE-2026-86487 1 Jetbrains 1 Youtrack 2026-09-07 3.1 Low
In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content
CVE-2026-86490 1 Jetbrains 1 Youtrack 2026-09-07 6.5 Medium
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint