Security Risk Category

Authorization Bypass Security Risks — Page 3

Published vulnerability pages connected to Authorization Bypass. Each page keeps one canonical URL and focused remediation guidance.

373 published Authorization Bypass risks

Authorization Bypass risks

Showing 73–108 of 373 published risks.

criticalEPSS 0.004

CVE-2026-54052 n8n-mcp vulnerability

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants' stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.

CVE-2026-54052authorization-bypassidor

Updated Jul 19, 2026

mediumEPSS 0.003

CVE-2026-55608 n8n-mcp vulnerability

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true could allow an authenticated tenant to access default-scope workflow_versions backups instead of being confined to the tenant scope, exposing or deleting workflow-version backups from prior single-tenant deployments or migrations. This issue is fixed in version 2.57.4.

CVE-2026-55608authorization-bypassinformation-disclosure

Updated Jul 19, 2026

mediumEPSS 0.003

pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read

The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract force generation of a full-site backup archive written to a publicly accessible directory, exposing wp-config.php database credentials, WordPress secret salts, and the complete PHP source tree. The resulting archive is deposited in the plugin's unprotected tmp/ directory at a predictable URL, making the extracted data accessible to unauthenticated visitors once the backup is triggered.

CVE-2026-14503wordpressphpauthorization-bypassinformation-disclosure

Updated Jul 19, 2026

mediumEPSS 0.003

ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary company locations in the ERP database.

CVE-2026-15349wordpresswoocommerceauthorization-bypass

Updated Jul 19, 2026

mediumEPSS 0.002

Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_* hooks and unconditionally calls delete_option() on four plugin options and delete_transient() on three transients tied to the plugin's API key cache and settings. This makes it possible for unauthenticated attackers to delete plugin options and transients, effectively resetting the plugin's API key/data cache and forcing the plugin to refetch state.

CVE-2026-8616wordpressnetwork-securityapi-securityauthorization-bypass

Updated Jul 19, 2026

mediumEPSS 0.005

Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to write .xls/.xlsx files to arbitrary locations on the server, which can be used to stage further attacks.

CVE-2026-15160wordpressauthorization-bypasspath-traversal

Updated Jul 19, 2026

highEPSS 0.004

LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including questions belonging to paid courses the attacker is not enrolled in.

CVE-2026-13765wordpressauthorization-bypassinformation-disclosure

Updated Jul 19, 2026

mediumEPSS 0.010

CVE-2026-44595 yamcs vulnerability

Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no privileges, could enumerate all user accounts in the system including their usernames, superuser status, and group memberships. This issue is fixed in versions 5.12.7 and 5.13.0.

CVE-2026-44595javaapi-securityauthorization-bypass

Updated Jul 18, 2026

highEPSS 0.025

CVE-2026-49170 windows 10 1809 vulnerability

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVE-2026-49170windowsapi-securityauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.021

CVE-2026-49805 windows 10 1607 vulnerability

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-49805windowsauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50297 windows 10 1607 vulnerability

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-50297windowsauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50311 windows 10 1607 vulnerability

Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.

CVE-2026-50311windowsauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50325 windows 10 1607 vulnerability

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-50325windowsauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50342 windows 11 24h2 vulnerability

Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-50342windowsauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.025

CVE-2026-50351 windows 10 1607 vulnerability

Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.

CVE-2026-50351windowsauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-58631 windows admin center vulnerability

Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

CVE-2026-58631windowsauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.005

CVE-2026-55052 sharepoint server vulnerability

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVE-2026-55052microsoftauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-58540 windows 10 1607 vulnerability

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-58540windowsauthorization-bypass

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-58545 windows 10 1607 vulnerability

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-58545linuxwindowsauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.007

CVE-2026-58617 365 copilot vulnerability

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-58617microsoftauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48348 animate vulnerability

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48348remote-code-executionauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48349 animate vulnerability

Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48349remote-code-executionauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48806 twig vulnerability

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0.

CVE-2026-48806phpauthorization-bypass

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48807 twig vulnerability

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.

CVE-2026-48807phpauthorization-bypass

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-48808 twig vulnerability

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.

CVE-2026-48808phpauthorization-bypass

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-49981 twig vulnerability

Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.

CVE-2026-49981phpauthorization-bypass

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-59259 n8n vulnerability

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential create or update permissions but without the externalSecret:list scope can embed external secret references into credentials in forms the static validation does not detect; these references resolve at workflow execution time, exposing secret values the user is not authorized to access. This issue only affects instances where an external secrets provider is configured and Advanced Permissions are in use.

CVE-2026-59259authorization-bypassidor

Updated Jul 17, 2026

criticalEPSS 0.007

CVE-2026-55040 in Microsoft SharePoint Server

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-55040microsoftweb-applicationauthentication-bypassauthorization-bypass

Updated Jul 16, 2026

highEPSS 0.005

CVE-2026-47301 in Microsoft Configuration Manager

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

CVE-2026-47301microsoftauthorization-bypassprivilege-escalation

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15768 in Google Chrome

Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15768browserauthorization-bypass

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15775 in Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15775browserauthorization-bypass

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15778 in Google Chrome

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-15778browserinput-validationauthorization-bypass

Updated Jul 16, 2026

criticalEPSS 0.002

CVE-2026-48321 in Adobe ColdFusion

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48321web-applicationauthorization-bypassprivilege-escalation

Updated Jul 16, 2026

criticalEPSS 0.002

CVE-2026-48327 in Adobe ColdFusion

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48327web-applicationremote-code-executionauthorization-bypass

Updated Jul 16, 2026

highEPSS 0.006

CVE-2026-48328 in Adobe ColdFusion

ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48328web-applicationinput-validationauthorization-bypassinformation-disclosure

Updated Jul 16, 2026

lowEPSS 0.004

CVE-2026-48329 in Adobe ColdFusion

ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.

CVE-2026-48329web-applicationauthentication-bypassauthorization-bypass

Updated Jul 16, 2026