Security Risk Category

Authorization Bypass Security Risks — Page 6

Published vulnerability pages connected to Authorization Bypass. Each page keeps one canonical URL and focused remediation guidance.

373 published Authorization Bypass risks

Authorization Bypass risks

Showing 181–216 of 373 published risks.

mediumEPSS 0.002

CVE-2026-62198 in OpenClaw

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization controls and execute restricted operations.

CVE-2026-62198npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62199 in OpenClaw

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and reachable, a lower-trust caller or configured input path can supply crafted environment variables to execute or persist actions beyond the caller's intended authorization.

CVE-2026-62199npmapi-securityremote-code-executionauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62200 in OpenClaw

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization.

CVE-2026-62200npmapi-securityremote-code-executionauthorization-bypass

Updated Jul 15, 2026

criticalEPSS 0.002

CVE-2026-59083 in Apache Tomcat

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVE-2026-59083javaweb-applicationinput-validationauthorization-bypass

Updated Jul 15, 2026

medium

CVE-2026-62393 in Apache Kylin

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

CVE-2026-62393javaapi-securityauthorization-bypass

Updated Jul 15, 2026

high

CVE-2026-58477 in Sustainable Irrigation Platform

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation.

CVE-2026-58477industrial-controlauthorization-bypasscsrf

Updated Jul 15, 2026

criticalCISA KEV

CVE-2026-56155 in Active Directory Federation Services

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

CVE-2026-56155windowsmicrosoftauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-56152 in Elastic Defend

Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.

CVE-2026-56152cloud-securityauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-53492 in containerd

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation permissions to bypass standard Kubernetes resource allocation and device plugin enforcement, injecting arbitrary CDI edits (such as device nodes and host mounts) into the restored container. Successful exploitation requires that the node has CDI enabled and contains a matching host CDI specification for the requested device; environments where CDI is disabled or lacking sensitive device specifications are not affected. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.

CVE-2026-53492cloud-securitydevopsinput-validationauthorization-bypass

Updated Jul 15, 2026

medium

CVE-2026-14340 in GitHub Enterprise Server

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because the authorization check only verified that the installation had read permissions on the target repository rather than verifying that the token's installation was explicitly granted access to that repository. An attacker who obtained a victim's user-to-server token could create issues, issue comments, commit comments, and private vulnerability reports on any public repository, appearing as the victim user with no indication of the app involvement. This vulnerability was fixed by adding a repository scope check for user-to-server tokens issued by global apps. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.

CVE-2026-14340api-securitydevopsauthorization-bypass

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54259 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the Wagtail admin could see the filename and name and URLs of documents and images in those collections. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54259pythonweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54261 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object itself is not exposed. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54261pythonweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54262 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54262pythonweb-applicationauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-8147 in MLflow

In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.

CVE-2026-8147pythonapi-securitydevopsauthorization-bypass

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-50746 in UniFi Connect Application

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

CVE-2026-50746network-securityremote-code-executionauthorization-bypass

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-54400 in UniFi Access Application

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

CVE-2026-54400network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-54407 in UniFi Protect Application

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.

CVE-2026-54407network-securityapi-securityauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-54408 in UniFi Protect Application

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.

CVE-2026-54408network-securityauthentication-bypassauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.001

CVE-2026-55110 in UniFi OS Server

A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.

CVE-2026-55110network-securityauthorization-bypasscsrf

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-55112 in UniFi OS with UniFi Protect

A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.

CVE-2026-55112network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-55113 in UniFi Talk Application

A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints.

CVE-2026-55113network-securityapi-securityauthorization-bypassdenial-of-service

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-55114 in UniFi Network Application

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

CVE-2026-55114network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-55116 in UniFi OS Devices

A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.

CVE-2026-55116network-securityauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-55118 in UniFi Network Application

A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

CVE-2026-55118network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-55119 in UniFi Talk Application

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.

CVE-2026-55119network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-56842 in UniFi Network Application

A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.

CVE-2026-56842network-securityauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-8079 in Progress Flowmon

In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.

CVE-2026-8079network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-9272 in Progress Flowmon ADS

In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.

CVE-2026-9272network-securitysql-injectionauthorization-bypass

Updated Jul 14, 2026

criticalEPSS 0.006

CVE-2026-44935 in SUSE Rancher Fleet

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

CVE-2026-44935cloud-securitydevopsauthorization-bypassinformation-disclosure

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-59093 Weaviate Vulnerability

Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The assignRoleToUser and assignRoleToGroup handlers (POST /authz/users/{id}/assign and /authz/groups/{id}/assign) authorize only that the caller may assign roles to the target user or group, not the permissions contained in the assigned roles, unlike role creation which enforces that a user can only create roles with permissions less than or equal to its own. A user holding only the delegated assign_and_revoke_users or assign_and_revoke_groups permission can assign the built-in admin role, or any high-privilege custom role, to itself or others, escalating to full administrative control of the database.

CVE-2026-59093web-applicationauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

mediumEPSS 0.004

CVE-2026-26145 Azure Synapse Vulnerability

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

CVE-2026-26145microsoftcloud-securityauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-54998 Microsoft Exchange Online Vulnerability

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

CVE-2026-54998microsoftauthorization-bypass

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-41123 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.

CVE-2026-41123network-securityauthorization-bypass

Updated Jul 14, 2026

mediumEPSS 0.001

CVE-2026-46730 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.

CVE-2026-46730network-securityremote-code-executionauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.005

CVE-2026-57983 edge chromium vulnerability

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-57983browsermicrosoftauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58282 edge chromium vulnerability

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58282browsermicrosoftauthorization-bypass

Updated Jul 14, 2026