Security Risk Category

API Security Risks — Page 3

Published vulnerability pages connected to API Security. Each page keeps one canonical URL and focused remediation guidance.

215 published API Security risks

API Security risks

Showing 73–108 of 215 published risks.

mediumEPSS 0.002

CVE-2026-55475 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata....

CVE-2026-55475phpapi-securityweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-57212 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final...

CVE-2026-57212network-securityapi-securitydenial-of-service

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-57219 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to...

CVE-2026-57219network-securityapi-securityinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-57221 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to...

CVE-2026-57221network-securityapi-securityauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-49844 in Apache Log4j API

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not...

CVE-2026-49844javaapi-securityinput-validation

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58024 in MediaWiki

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiUserrights.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58024phpapi-securityweb-applicationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58027 in MediaWiki AbuseFilter

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php. This issue affects AbuseFilter: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58027phpapi-securityweb-applicationinformation-disclosure

Updated Jul 15, 2026

infoEPSS 0.003

CVE-2026-58028 in MediaWiki and CentralAuth

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation CentralAuth. This vulnerability is associated with program files includes/Api/ApiFormatBase.Php, includes/Api/ApiHelp.Php, includes/ResourceLoader/Module.Php, includes/Hooks/Handlers/PageDisplayHookHandler.Php, includes/LogFormatter/PermissionChangeLogFormatter.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9; CentralAuth: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58028phpapi-securityweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58029 in MediaWiki

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiChangeAuthenticationData.Php, includes/Api/ApiLinkAccount.Php, includes/Api/ApiRemoveAuthenticationData.Php, includes/Specials/SpecialLinkAccounts.Php, includes/Specials/SpecialUnlinkAccounts.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58029phpapi-securityweb-applicationauthentication-bypass

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-58032 in MediaWiki

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Api/index.Js. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58032phpapi-securityweb-applicationxss

Updated Jul 15, 2026

lowEPSS 0.002

CVE-2026-58036 in MediaWiki

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryAllUsers.Php, includes/Api/ApiQueryUsers.Php, includes/Permissions/PermissionManager.Php, includes/User/UserGroupManager.Php.

CVE-2026-58036phpapi-securityweb-applicationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56148 in Elasticsearch

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.

CVE-2026-56148api-securitydevopsdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56149 in Elasticsearch

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.

CVE-2026-56149api-securitydevopsdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56150 in Elastic Fleet Server

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.

CVE-2026-56150api-securitydevopsdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-10085 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688

CVE-2026-10085api-securityweb-applicationauthorization-bypassdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-10103 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs in channels shared with that remote.. Mattermost Advisory ID: MMSA-2026-00689

CVE-2026-10103api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-10106 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690

CVE-2026-10106api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6850 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser.. Mattermost Advisory ID: MMSA-2026-00658

CVE-2026-6850api-securityweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-9571 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680

CVE-2026-9571api-securityweb-applicationauthentication-bypass

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-9597 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681

CVE-2026-9597api-securityweb-applicationauthentication-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-9708 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-00683

CVE-2026-9708api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

criticalEPSS 0.006

CVE-2026-41041 in Apache Gravitino

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue.

CVE-2026-41041javaapi-securityinput-validationpath-traversal

Updated Jul 15, 2026

mediumEPSS 0.005

CVE-2026-49876 in Apache Gravitino

Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 through 1.2.1. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

CVE-2026-49876javaapi-securitycloud-securityssrf

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6541 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653

CVE-2026-6541api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

lowEPSS 0.002

CVE-2026-9820 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671

CVE-2026-9820api-securityweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-9824 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2026-00676

CVE-2026-9824api-securityweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62186 in OpenClaw

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to bypass admin authorization policies and execute restricted operations.

CVE-2026-62186npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62187 in OpenClaw Feishu

OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. Impact depends on the operator's configuration and whether lower-trust input can reach the affected feature.

CVE-2026-62187npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62188 in OpenClaw Feishu

OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in version 2026.6.9.

CVE-2026-62188npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62190 in OpenClaw

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval binding and perform unauthorized operations when the affected feature is enabled.

CVE-2026-62190npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62191 in OpenClaw

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester authorization and execute privileged operations when the affected feature is enabled and reachable.

CVE-2026-62191npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62192 in OpenClaw

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider requester authorization and execute restricted operations.

CVE-2026-62192npmapi-securityauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-62193 in OpenClaw

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is fixed in 2026.6.9.

CVE-2026-62193npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62194 in OpenClaw

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled features to escalate privileges and perform unauthorized actions when the feature is reachable.

CVE-2026-62194npmapi-securityauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62195 in OpenClaw

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist actions beyond their intended permissions.

CVE-2026-62195npmapi-securityauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62196 in OpenClaw

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.

CVE-2026-62196npmapi-securityauthorization-bypass

Updated Jul 15, 2026