Security Risk Category

Authorization Bypass Security Risks

Published vulnerability pages connected to Authorization Bypass. Each page keeps one canonical URL and focused remediation guidance.

373 published Authorization Bypass risks

Authorization Bypass risks

Showing 1–36 of 373 published risks.

medium

CVE-2026-65472 Kit (formerly ConvertKit) vulnerability

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

CVE-2026-65472authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65476 Civi vulnerability

Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.

CVE-2026-65476authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65478 ListingPro vulnerability

Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.

CVE-2026-65478authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65479 Reviewer vulnerability

Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.

CVE-2026-65479authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65484 Style Kits vulnerability

Contributor Broken Access Control in Style Kits <= 2.6.5 versions.

CVE-2026-65484authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65485 Content Control vulnerability

Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.

CVE-2026-65485authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65487 Photography vulnerability

Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.

CVE-2026-65487authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65486 Event post vulnerability

Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.

CVE-2026-65486authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65489 LA-Studio Element Kit for Elementor vulnerability

Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

CVE-2026-65489authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65491 Query Wrangler vulnerability

Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.

CVE-2026-65491authorization-bypass

Updated Jul 24, 2026

high

CVE-2026-65495 Dokan Pro vulnerability

Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.

CVE-2026-65495authorization-bypass

Updated Jul 24, 2026

high

CVE-2026-65500 Manual - Documentation, Knowledge Base & Education WordPress Theme vulnerability

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVE-2026-65500wordpressauthorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65499 PeproDev Ultimate Invoice vulnerability

Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVE-2026-65499authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65506 MP3 Audio Player for Music, Radio & Podcast by Sonaar vulnerability

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

CVE-2026-65506authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65525 Civi Framework vulnerability

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

CVE-2026-65525authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65524 Avada Custom Branding vulnerability

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

CVE-2026-65524authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65530 TemplateSpare vulnerability

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

CVE-2026-65530authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65529 Graphina vulnerability

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

CVE-2026-65529authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65531 Qubely vulnerability

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

CVE-2026-65531authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65537 Cyr to Lat reloaded – transliteration of links and file names vulnerability

Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.

CVE-2026-65537authorization-bypass

Updated Jul 24, 2026

high

CVE-2026-65895 grav vulnerability

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.

CVE-2026-65895phpapi-securityauthorization-bypass

Updated Jul 24, 2026

high

CVE-2026-65916 cyberpanel vulnerability

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status files, and remove database records belonging to other tenants.

CVE-2026-65916authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65696 overseerr vulnerability

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters. Attackers can exploit the missing ownership check in the affected handlers to access target user records without the filteredFields filter, leaking sensitive data including email addresses and plexId values.

CVE-2026-65696api-securityauthorization-bypassidor

Updated Jul 24, 2026

critical

CVE-2026-65760 Easy Store extension for Joomla vulnerability

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.

CVE-2026-65760joomlaauthorization-bypassinformation-disclosure

Updated Jul 24, 2026

high

CVE-2026-65759 Easy Store extension for Joomla vulnerability

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.

CVE-2026-65759joomlaauthorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-47755 itflow vulnerability

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue.

CVE-2026-47755authorization-bypassidor

Updated Jul 24, 2026

low

CVE-2026-65699 AgentGPT vulnerability

AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_task_count functions look up the target AgentRun using the client-supplied run_id without confirming the run belongs to the requesting user, enabling an attacker who obtains a valid run_id to corrupt task history, exhaust the per-run loop budget, and drive LLM costs against the victim's run.

CVE-2026-65699authorization-bypassidor

Updated Jul 24, 2026

critical

CVE-2026-47724 nebula-mesh vulnerability

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API trusts the bearer token for authorisation; per-CA ownership is enforced only in the Web layer." The Web UI gates state-changing routes through `loadAccessibleCA` (`internal/web/cas.go`); CA-management endpoints in `internal/api/cas.go` ALSO have proper `canAccessCA` gates. The gap is on the host, network, firewall, mobile-bundle, and most operator endpoints. Combined with the per-operator CA model from ADR 0002, this gives any non-admin operator API key broad cross-tenant access — instant privilege escalation in the worst case. Version 0.3.4 fixes the issue.

CVE-2026-47724network-securityapi-securityauthorization-bypassprivilege-escalation

Updated Jul 24, 2026

high

CVE-2026-35425 Azure API Management (APIM) vulnerability

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

CVE-2026-35425api-securityauthorization-bypass

Updated Jul 24, 2026

critical

CVE-2026-56160 Azure Red Hat OpenShift (ARO) vulnerability

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

CVE-2026-56160authorization-bypass

Updated Jul 24, 2026

critical

CVE-2026-58275 Azure DNS vulnerability

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-58275authorization-bypass

Updated Jul 24, 2026

medium

Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing record-access link to an attacker-controlled email address, granting full read and edit access to the victim's stored personally identifiable information including names, email addresses, phone numbers, and any other fields collected in the participant database. An attacker can harvest a valid nonce with a plain unauthenticated GET request to any page rendering the public signup or record form, then POST action=update with an arbitrary id value to overwrite any record; chaining a subsequent action=retrieve then delivers the private-access link to the attacker-controlled mailbox.

CVE-2026-11354wordpressauthorization-bypassinformation-disclosure

Updated Jul 24, 2026

medium

Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying status=succeeded and captured=true, triggering payment_complete() and downstream fulfillment flows with an attacker-supplied transaction ID. Exploitation requires the merchant to have left the webhook_secret_test or webhook_secret_live option blank, which is the plugin's default state until a Stripe-issued whsec_ value is manually configured; once a non-empty secret is set, the signature verification cannot be bypassed.

CVE-2026-12654wordpresswoocommercenetwork-securityauthorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-12702 Octopus Server vulnerability

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

CVE-2026-12702authorization-bypass

Updated Jul 24, 2026

critical

CVE-2026-15704 Eclipse BaSyx Go Components vulnerability

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However, the ABAC middleware evaluated the original request path including the trailing slash. If ABAC route lookup did not find a matching slash-suffixed route, the request was passed onward and the router then stripped the slash and executed the protected handler without the intended ABAC authorization decision and without the expected ABAC query filters. An unauthenticated or unauthorized network attacker could append a trailing slash to protected API routes to reach handlers that should have been denied by ABAC policy. Depending on the exposed component, HTTP method, and deployed policy, this could allow unauthorized read, create, update, delete, or upload operations. The issue affects ABAC-enabled deployments of services that use the shared router and ABAC middleware, including AAS Repository, Submodel Repository, AAS Registry, Submodel Registry, Concept Description Repository, Discovery, AAS Environment upload, and related services. The issue is fixed in Eclipse BaSyx Go Components v1.0.1.

CVE-2026-15704network-securityapi-securityauthorization-bypass

Updated Jul 24, 2026

high

EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action

The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities and the upload_files capability to any non-administrator WordPress role or user, escalating their privileges within the site. The administrator role is protected by an early-return guard in update_role_caps(), so only non-administrator roles and individual users can be targeted; however, the same unauthenticated exposure also allows attackers to enumerate all WordPress users with their IDs and display names, disclose role and user capability state along with nonce values, and tamper with event-to-user term assignments.

CVE-2026-10033wordpressauthorization-bypassprivilege-escalation

Updated Jul 24, 2026