Security Risk Category

Authorization Bypass Security Risks — Page 5

Published vulnerability pages connected to Authorization Bypass. Each page keeps one canonical URL and focused remediation guidance.

373 published Authorization Bypass risks

Authorization Bypass risks

Showing 145–180 of 373 published risks.

highEPSS 0.005

CVE-2026-47984 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.

CVE-2026-47984phpweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-47988 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.

CVE-2026-47988phpweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.185

CVE-2026-47996 in Adobe Commerce

Adobe Commerce has an authorization issue that can let a high-privilege attacker bypass rules and read data.

CVE-2026-47996phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-47997 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.

CVE-2026-47997phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-47998 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.

CVE-2026-47998phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-48489 in Symfony Security HTTP

Symfony Security HTTP can let a failed login request reach protected GET routes when failure forwarding is enabled.

CVE-2026-48489phpweb-applicationauthentication-bypassauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.4 - Missing Authorization

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.

CVE-2026-57812wordpressauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.11 - Missing Authorization

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.

CVE-2026-59523wordpressauthorization-bypass

Updated Jul 15, 2026

lowEPSS 0.005

CVE-2026-45066 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can bypass allowed link or media host rules because some URLs are parsed differently than expected.

CVE-2026-45066phpweb-applicationinput-validationauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-9341 in Academy LMS

Academy LMS lets a logged-in subscriber change a user id value and read, change, or delete another user's private lesson notes.

CVE-2026-9341wordpressauthorization-bypassidor

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-61952 in Bulk Edit Products for WooCommerce - WP Sheet Editor

Bulk Edit Products for WooCommerce - WP Sheet Editor misses an authorization check, so an author-level user can run an action they should not be allowed to run.

CVE-2026-61952wordpresswoocommerceauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-5135 in Red Hat Satellite

A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.

CVE-2026-5135linuxdevopsweb-applicationauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-5138 in Red Hat Satellite

A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.

CVE-2026-5138linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-5142 in Red Hat Satellite

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.

CVE-2026-5142linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58029 in MediaWiki

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiChangeAuthenticationData.Php, includes/Api/ApiLinkAccount.Php, includes/Api/ApiRemoveAuthenticationData.Php, includes/Specials/SpecialLinkAccounts.Php, includes/Specials/SpecialUnlinkAccounts.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58029phpapi-securityweb-applicationauthentication-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-57830 in Helix Ultimate for Joomla

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

CVE-2026-57830joomlaauthorization-bypassfile-writefile-deletion

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-10085 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688

CVE-2026-10085api-securityweb-applicationauthorization-bypassdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-10103 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs in channels shared with that remote.. Mattermost Advisory ID: MMSA-2026-00689

CVE-2026-10103api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-10106 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690

CVE-2026-10106api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-9708 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-00683

CVE-2026-9708api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6541 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653

CVE-2026-6541api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

lowEPSS 0.002

CVE-2026-9820 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671

CVE-2026-9820api-securityweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-9824 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2026-00676

CVE-2026-9824api-securityweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-59245 in Apache Airflow Providers FAB

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.2 or later, which disambiguates the resource-name collision.

CVE-2026-59245pythondevopsauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62186 in OpenClaw

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to bypass admin authorization policies and execute restricted operations.

CVE-2026-62186npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62187 in OpenClaw Feishu

OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. Impact depends on the operator's configuration and whether lower-trust input can reach the affected feature.

CVE-2026-62187npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62188 in OpenClaw Feishu

OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in version 2026.6.9.

CVE-2026-62188npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62189 in OpenClaw

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

CVE-2026-62189npmauthorization-bypasspath-traversalfile-write

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62190 in OpenClaw

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval binding and perform unauthorized operations when the affected feature is enabled.

CVE-2026-62190npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62191 in OpenClaw

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester authorization and execute privileged operations when the affected feature is enabled and reachable.

CVE-2026-62191npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62192 in OpenClaw

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider requester authorization and execute restricted operations.

CVE-2026-62192npmapi-securityauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-62193 in OpenClaw

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is fixed in 2026.6.9.

CVE-2026-62193npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62194 in OpenClaw

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled features to escalate privileges and perform unauthorized actions when the feature is reachable.

CVE-2026-62194npmapi-securityauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62195 in OpenClaw

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist actions beyond their intended permissions.

CVE-2026-62195npmapi-securityauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62196 in OpenClaw

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.

CVE-2026-62196npmapi-securityauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-62197 in OpenClaw

OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.

CVE-2026-62197npmbrowserapi-securityauthorization-bypass

Updated Jul 15, 2026