Security Risk Category
Authorization Bypass Security Risks
Published vulnerability pages connected to Authorization Bypass. Each page keeps one canonical URL and focused remediation guidance.
373 published Authorization Bypass risks
Authorization Bypass risks
Showing 1–36 of 373 published risks.
CVE-2026-65472 Kit (formerly ConvertKit) vulnerability
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
Updated Jul 24, 2026
CVE-2026-65476 Civi vulnerability
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
Updated Jul 24, 2026
CVE-2026-65478 ListingPro vulnerability
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
Updated Jul 24, 2026
CVE-2026-65479 Reviewer vulnerability
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
Updated Jul 24, 2026
CVE-2026-65484 Style Kits vulnerability
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
Updated Jul 24, 2026
CVE-2026-65485 Content Control vulnerability
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
Updated Jul 24, 2026
CVE-2026-65487 Photography vulnerability
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
Updated Jul 24, 2026
CVE-2026-65486 Event post vulnerability
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
Updated Jul 24, 2026
CVE-2026-65489 LA-Studio Element Kit for Elementor vulnerability
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Updated Jul 24, 2026
CVE-2026-65491 Query Wrangler vulnerability
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
Updated Jul 24, 2026
CVE-2026-65495 Dokan Pro vulnerability
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
Updated Jul 24, 2026
CVE-2026-65500 Manual - Documentation, Knowledge Base & Education WordPress Theme vulnerability
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
Updated Jul 24, 2026
CVE-2026-65499 PeproDev Ultimate Invoice vulnerability
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
Updated Jul 24, 2026
CVE-2026-65506 MP3 Audio Player for Music, Radio & Podcast by Sonaar vulnerability
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
Updated Jul 24, 2026
CVE-2026-65525 Civi Framework vulnerability
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
Updated Jul 24, 2026
CVE-2026-65524 Avada Custom Branding vulnerability
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
Updated Jul 24, 2026
CVE-2026-65530 TemplateSpare vulnerability
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
Updated Jul 24, 2026
CVE-2026-65529 Graphina vulnerability
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
Updated Jul 24, 2026
CVE-2026-65531 Qubely vulnerability
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
Updated Jul 24, 2026
CVE-2026-65537 Cyr to Lat reloaded – transliteration of links and file names vulnerability
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
Updated Jul 24, 2026
CVE-2026-65895 grav vulnerability
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.
Updated Jul 24, 2026
CVE-2026-65916 cyberpanel vulnerability
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status files, and remove database records belonging to other tenants.
Updated Jul 24, 2026
CVE-2026-65696 overseerr vulnerability
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters. Attackers can exploit the missing ownership check in the affected handlers to access target user records without the filteredFields filter, leaking sensitive data including email addresses and plexId values.
Updated Jul 24, 2026
CVE-2026-65760 Easy Store extension for Joomla vulnerability
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.
Updated Jul 24, 2026
CVE-2026-65759 Easy Store extension for Joomla vulnerability
Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.
Updated Jul 24, 2026
CVE-2026-47755 itflow vulnerability
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue.
Updated Jul 24, 2026
CVE-2026-65699 AgentGPT vulnerability
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_task_count functions look up the target AgentRun using the client-supplied run_id without confirming the run belongs to the requesting user, enabling an attacker who obtains a valid run_id to corrupt task history, exhaust the per-run loop budget, and drive LLM costs against the victim's run.
Updated Jul 24, 2026
CVE-2026-47724 nebula-mesh vulnerability
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API trusts the bearer token for authorisation; per-CA ownership is enforced only in the Web layer." The Web UI gates state-changing routes through `loadAccessibleCA` (`internal/web/cas.go`); CA-management endpoints in `internal/api/cas.go` ALSO have proper `canAccessCA` gates. The gap is on the host, network, firewall, mobile-bundle, and most operator endpoints. Combined with the per-operator CA model from ADR 0002, this gives any non-admin operator API key broad cross-tenant access — instant privilege escalation in the worst case. Version 0.3.4 fixes the issue.
Updated Jul 24, 2026
CVE-2026-35425 Azure API Management (APIM) vulnerability
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Updated Jul 24, 2026
CVE-2026-56160 Azure Red Hat OpenShift (ARO) vulnerability
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Updated Jul 24, 2026
CVE-2026-58275 Azure DNS vulnerability
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Updated Jul 24, 2026
Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing record-access link to an attacker-controlled email address, granting full read and edit access to the victim's stored personally identifiable information including names, email addresses, phone numbers, and any other fields collected in the participant database. An attacker can harvest a valid nonce with a plain unauthenticated GET request to any page rendering the public signup or record form, then POST action=update with an arbitrary id value to overwrite any record; chaining a subsequent action=retrieve then delivers the private-access link to the attacker-controlled mailbox.
Updated Jul 24, 2026
Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying status=succeeded and captured=true, triggering payment_complete() and downstream fulfillment flows with an attacker-supplied transaction ID. Exploitation requires the merchant to have left the webhook_secret_test or webhook_secret_live option blank, which is the plugin's default state until a Stripe-issued whsec_ value is manually configured; once a non-empty secret is set, the signature verification cannot be bypassed.
Updated Jul 24, 2026
CVE-2026-12702 Octopus Server vulnerability
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
Updated Jul 24, 2026
CVE-2026-15704 Eclipse BaSyx Go Components vulnerability
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However, the ABAC middleware evaluated the original request path including the trailing slash. If ABAC route lookup did not find a matching slash-suffixed route, the request was passed onward and the router then stripped the slash and executed the protected handler without the intended ABAC authorization decision and without the expected ABAC query filters. An unauthenticated or unauthorized network attacker could append a trailing slash to protected API routes to reach handlers that should have been denied by ABAC policy. Depending on the exposed component, HTTP method, and deployed policy, this could allow unauthorized read, create, update, delete, or upload operations. The issue affects ABAC-enabled deployments of services that use the shared router and ABAC middleware, including AAS Repository, Submodel Repository, AAS Registry, Submodel Registry, Concept Description Repository, Discovery, AAS Environment upload, and related services. The issue is fixed in Eclipse BaSyx Go Components v1.0.1.
Updated Jul 24, 2026
EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action
The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities and the upload_files capability to any non-administrator WordPress role or user, escalating their privileges within the site. The administrator role is protected by an early-return guard in update_role_caps(), so only non-administrator roles and individual users can be targeted; however, the same unauthenticated exposure also allows attackers to enumerate all WordPress users with their IDs and display names, disclose role and user capability state along with nonce values, and tamper with event-to-user term assignments.
Updated Jul 24, 2026
