CVE & CISA-KEV Catalog
| Severity | Description | ||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-63349 | High | 7.0 v4 | - | - | -No fix available yet | 2026-09-18 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_process() forwards the group argument to the backend instead of extra_groups. A caller that supplies extra_groups=[] to clear inherited supplementary groups can therefore launch a child that retains the parent process groups, undermining a privilege-dropping boundary. If group is also supplied, the integer group value is passed where an iterable of supplementary groups is expected and the launch can fail with TypeError. This issue affects POSIX applications that rely on AnyIO subprocess helpers to launch less-privileged child processes. This issue is fixed in ve |
| CVE-2026-93504 | Medium | 6.3 v3 | - | - | -No fix available yet | 2026-09-18 | A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The name of the patch is 05b4f9efeb79e9d72a693232334d7529687f896f. It is advisable to implement a patch to correct this issue. |
| CVE-2026-73461 | High | 8.0 v3 | - | - | -No fix available yet | 2026-09-16 | On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig requests such as NETCONF. |
| CVE-2026-91930 | High | 7.5 v3 | - | - | -No fix available yet | 2026-09-15 | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints. |
| CVE-2026-90856 | High | 7.3 v3 | 0.3% | - | -No fix available yet | 2026-09-15 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. |
| CVE-2026-90851 | Medium | 6.3 v3 | 0.2% | - | -No fix available yet | 2026-09-15 | A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been published and may be used. |
| CVE-2026-90812 | Medium | 4.3 v3 | 0.2% | - | -No fix available yet | 2026-09-14 | A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-90810 | Medium | 6.3 v3 | 0.2% | - | -No fix available yet | 2026-09-14 | A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-86830 | High | 7.2 v3 | 0.4% | - | -No fix available yet | 2026-09-14 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. |
| CVE-2026-90787 | High | 7.3 v3 | 0.4% | - | -No fix available yet | 2026-09-14 | A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-78330 | Critical | 9.8 v3 | 0.6% | - | -No fix available yet | 2026-09-14 | Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue. |
| CVE-2026-90566 | High | 7.3 v3 | 0.5% | - | -No fix available yet | 2026-09-13 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-90565 | Medium | 5.3 v3 | 0.5% | - | -No fix available yet | 2026-09-13 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-90523 | High | 7.3 v3 | 0.5% | - | -No fix available yet | 2026-09-13 | A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue. |
| CVE-2026-90520 | Medium | 6.3 v3 | 0.4% | - | -No fix available yet | 2026-09-13 | A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue. |
| CVE-2026-90518 | Medium | 6.3 v3 | 0.2% | - | -No fix available yet | 2026-09-13 | A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. |
| CVE-2026-90507 | Medium | 6.3 v3 | 0.4% | - | -No fix available yet | 2026-09-13 | A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer. |
| CVE-2026-90501 | Medium | 6.3 v3 | 0.2% | - | -No fix available yet | 2026-09-13 | A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
| CVE-2026-90499 | Medium | 5.4 v3 | 0.3% | - | -No fix available yet | 2026-09-13 | A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. |
| CVE-2026-90493 | High | 8.8 v3 | 0.1% | - | -No fix available yet | 2026-09-13 | A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for Windows up to and including 6.42 Build 63 installs idmwfp.sys, a Windows kernel driver that exposes the \.\IDMWFP device interface to authenticated local users. The device object is created with an access control descriptor equivalent to D:P(A;;GA;;;AU), granting Authenticated Users generic access to the driver. The driver's IOCTL 0x12C028 handler accepts registry-operation subcommands 0x0C through 0x0F and processes caller-controlled registry paths and values. These handlers do n |
| CVE-2026-90487 | Medium | 4.3 v3 | 0.2% | - | -No fix available yet | 2026-09-12 | A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. |
| CVE-2026-62106 | High | 8.8 v3 | 0.3% | - | -No fix available yet | 2026-09-11 | Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions. |
| CVE-2026-62102 | High | 8.8 v3 | 0.3% | - | -No fix available yet | 2026-09-11 | Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions. |
| CVE-2026-8303 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-09-11 | Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5. |
| CVE-2026-81805 | High | 8.1 v3 | 0.2% | - | -No fix available yet | 2026-09-10 | Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions. |
| CVE-2026-15140 | High | 7.7 v4 | 0.2% | - | -No fix available yet | 2026-09-09 | A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster. |
| CVE-2026-86804 | Medium | 5.3 v3 | 0.4% | - | -No fix available yet | 2026-09-08 | A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. Upgrading to version 1.11.11 is able to resolve this issue. The identifier of the patch is 842eec791377ddcbea5cd639bc065eaa4801d656. It is suggested to upgrade the affected component. |
| CVE-2026-77654 | Medium | 6.1 v4 | 0.1% | - | -No fix available yet | 2026-09-08 | Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30. |
| CVE-2026-85400 | High | 7.5 v4 | 0.4% | - | -No fix available yet | 2026-09-08 | Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6. |
| CVE-2026-81792 | Medium | 6.5 v3 | 0.2% | - | -No fix available yet | 2026-09-08 | Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions. |
| CVE-2026-86516 | Medium | 4.7 v3 | 0.2% | - | -No fix available yet | 2026-09-08 | A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue. |
| CVE-2026-86512 | Medium | 6.3 v3 | 0.2% | - | -No fix available yet | 2026-09-08 | A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-86500 | Medium | 5.5 v3 | 0.2% | - | -No fix available yet | 2026-09-07 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin |
| CVE-2026-86482 | High | 8.8 v3 | 0.2% | - | -No fix available yet | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation |
| CVE-2026-86285 | Medium | 4.3 v3 | 0.2% | - | -No fix available yet | 2026-09-07 | A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results in improper access controls. The attack may be launched remotely. The exploit is now public and may be used. The patch is identified as 4e406c41c4c8060a5795e74c66fb96362e54f400. It is advisable to implement a patch to correct this issue. |
| CVE-2026-86275 | Medium | 5.3 v3 | 0.3% | - | -No fix available yet | 2026-09-07 | A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used. |
| CVE-2026-86228 | Medium | 4.3 v3 | 0.2% | - | -No fix available yet | 2026-09-06 | A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component. |
| CVE-2026-86212 | Medium | 4.3 v3 | 0.3% | - | -No fix available yet | 2026-09-06 | A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch. |
| CVE-2026-86153 | Critical | 9.1 v3 | 0.4% | - | -No fix available yet | 2026-09-06 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible. |
| CVE-2026-85514 | Medium | 6.3 v3 | 0.3% | - | -No fix available yet | 2026-09-04 | A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API Key Handler. Such manipulation of the argument api_key_api.user leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-85513 | Medium | 6.3 v3 | 0.2% | - | -No fix available yet | 2026-09-04 | A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp RBAC backend. This manipulation of the argument User causes improper privilege management. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Prior advisory CVE-2022-44009 was reported as a follow-up on the same sink, but this issue is distinct: it needs no Jinja RBAC und affects default install with RBAC disabled. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-85401 | Medium | 6.3 v3 | 0.3% | - | -No fix available yet | 2026-09-04 | A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 23.0.4 can resolve this issue. This patch is called ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec. It is suggested to upgrade the affected component. |
| CVE-2026-85241 | Medium | 6.3 v3 | 0.3% | - | -No fix available yet | 2026-09-03 | A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component. |
| CVE-2026-84814 | Critical | 9.8 v3 | 0.4% | - | -No fix available yet | 2026-09-03 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. |
| CVE-2026-84756 | High | 7.1 v3 | 0.2% | - | -No fix available yet | 2026-09-03 | Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions. |
| CVE-2026-84807 | Medium | 5.4 v3 | 0.1% | - | -No fix available yet | 2026-09-02 | Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or activity whose name matches an existing team; because the endpoints POST /api/customers/{id}/team, POST /api/projects/{id}/team, and POST /api/activities/{id}/team reuse an existing team of the same name and add the current user as teamlead without verifying that the user is authorized to manage that team, the attacker gains unauthorized team-lead (administration) rights over the existing team. Fixed in 2.65.0. |
| CVE-2026-81769 | High | 8.8 v3 | 0.3% | - | -No fix available yet | 2026-09-02 | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. |
| CVE-2026-81294 | Critical | 9.8 v3 | 0.3% | - | -No fix available yet | 2026-09-02 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. |
| CVE-2026-84115 | High | 8.3 v3 | 0.3% | - | -No fix available yet | 2026-09-01 | A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 is sufficient to fix this issue. It is recommended to upgrade the affected component. |
| CVE-2026-81297 | High | 7.5 v3 | 0.3% | - | -No fix available yet | 2026-08-31 | Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. |
- HighCVSS 7.0 v4·EPSS -·No fix yet
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_process() forwards the group argument to the backend instead of extra_groups. A caller that supplies extra_groups=[] to clear inherited supplementary groups can therefore launch a child that retains the parent process groups, undermining a privilege-dropping boundary. If group is also supplied, the integer group value is passed where an iterable of supplementary groups is expected and the launch can fail with TypeError. This issue affects POSIX applications that rely on AnyIO subprocess helpers to launch less-privileged child processes. This issue is fixed in ve
Published 2026-09-18
- MediumCVSS 6.3 v3·EPSS -·No fix yet
A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The name of the patch is 05b4f9efeb79e9d72a693232334d7529687f896f. It is advisable to implement a patch to correct this issue.
Published 2026-09-18
- HighCVSS 8.0 v3·EPSS -·No fix yet
On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig requests such as NETCONF.
Published 2026-09-16
- HighCVSS 7.5 v3·EPSS -·No fix yet
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
Published 2026-09-15
- HighCVSS 7.3 v3·EPSS 0.3%·No fix yet
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Published 2026-09-15
- MediumCVSS 6.3 v3·EPSS 0.2%·No fix yet
A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Published 2026-09-15
- MediumCVSS 4.3 v3·EPSS 0.2%·No fix yet
A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published 2026-09-14
- MediumCVSS 6.3 v3·EPSS 0.2%·No fix yet
A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published 2026-09-14
- HighCVSS 7.2 v3·EPSS 0.4%·No fix yet
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Published 2026-09-14
- HighCVSS 7.3 v3·EPSS 0.4%·No fix yet
A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Published 2026-09-14
- CriticalCVSS 9.8 v3·EPSS 0.6%·No fix yet
Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published 2026-09-14
- HighCVSS 7.3 v3·EPSS 0.5%·No fix yet
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Published 2026-09-13
- MediumCVSS 5.3 v3·EPSS 0.5%·No fix yet
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published 2026-09-13
- HighCVSS 7.3 v3·EPSS 0.5%·No fix yet
A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.
Published 2026-09-13
- MediumCVSS 6.3 v3·EPSS 0.4%·No fix yet
A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue.
Published 2026-09-13
- MediumCVSS 6.3 v3·EPSS 0.2%·No fix yet
A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Published 2026-09-13
- MediumCVSS 6.3 v3·EPSS 0.4%·No fix yet
A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Published 2026-09-13
- MediumCVSS 6.3 v3·EPSS 0.2%·No fix yet
A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published 2026-09-13
- MediumCVSS 5.4 v3·EPSS 0.3%·No fix yet
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published 2026-09-13
- HighCVSS 8.8 v3·EPSS 0.1%·No fix yet
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for Windows up to and including 6.42 Build 63 installs idmwfp.sys, a Windows kernel driver that exposes the \.\IDMWFP device interface to authenticated local users. The device object is created with an access control descriptor equivalent to D:P(A;;GA;;;AU), granting Authenticated Users generic access to the driver. The driver's IOCTL 0x12C028 handler accepts registry-operation subcommands 0x0C through 0x0F and processes caller-controlled registry paths and values. These handlers do n
Published 2026-09-13
- MediumCVSS 4.3 v3·EPSS 0.2%·No fix yet
A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published 2026-09-12
- HighCVSS 8.8 v3·EPSS 0.3%·No fix yet
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
Published 2026-09-11
- HighCVSS 8.8 v3·EPSS 0.3%·No fix yet
Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
Published 2026-09-11
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.
Published 2026-09-11
- HighCVSS 8.1 v3·EPSS 0.2%·No fix yet
Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Published 2026-09-10
- HighCVSS 7.7 v4·EPSS 0.2%·No fix yet
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended, potentially resulting in elevated privileges within the Kubernetes cluster.
Published 2026-09-09
- MediumCVSS 5.3 v3·EPSS 0.4%·No fix yet
A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. Upgrading to version 1.11.11 is able to resolve this issue. The identifier of the patch is 842eec791377ddcbea5cd639bc065eaa4801d656. It is suggested to upgrade the affected component.
Published 2026-09-08
- MediumCVSS 6.1 v4·EPSS 0.1%·No fix yet
Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Published 2026-09-08
- HighCVSS 7.5 v4·EPSS 0.4%·No fix yet
Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.
Published 2026-09-08
- MediumCVSS 6.5 v3·EPSS 0.2%·No fix yet
Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.
Published 2026-09-08
- MediumCVSS 4.7 v3·EPSS 0.2%·No fix yet
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.
Published 2026-09-08
- MediumCVSS 6.3 v3·EPSS 0.2%·No fix yet
A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Published 2026-09-08
- MediumCVSS 5.5 v3·EPSS 0.2%·No fix yet
In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
Published 2026-09-07
- HighCVSS 8.8 v3·EPSS 0.2%·No fix yet
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
Published 2026-09-07
- MediumCVSS 4.3 v3·EPSS 0.2%·No fix yet
A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results in improper access controls. The attack may be launched remotely. The exploit is now public and may be used. The patch is identified as 4e406c41c4c8060a5795e74c66fb96362e54f400. It is advisable to implement a patch to correct this issue.
Published 2026-09-07
- MediumCVSS 5.3 v3·EPSS 0.3%·No fix yet
A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Published 2026-09-07
- MediumCVSS 4.3 v3·EPSS 0.2%·No fix yet
A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component.
Published 2026-09-06
- MediumCVSS 4.3 v3·EPSS 0.3%·No fix yet
A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.
Published 2026-09-06
- CriticalCVSS 9.1 v3·EPSS 0.4%·No fix yet
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.
Published 2026-09-06
- MediumCVSS 6.3 v3·EPSS 0.3%·No fix yet
A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API Key Handler. Such manipulation of the argument api_key_api.user leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published 2026-09-04
- MediumCVSS 6.3 v3·EPSS 0.2%·No fix yet
A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp RBAC backend. This manipulation of the argument User causes improper privilege management. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Prior advisory CVE-2022-44009 was reported as a follow-up on the same sink, but this issue is distinct: it needs no Jinja RBAC und affects default install with RBAC disabled. The project was informed of the problem early through an issue report but has not responded yet.
Published 2026-09-04
- MediumCVSS 6.3 v3·EPSS 0.3%·No fix yet
A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 23.0.4 can resolve this issue. This patch is called ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec. It is suggested to upgrade the affected component.
Published 2026-09-04
- MediumCVSS 6.3 v3·EPSS 0.3%·No fix yet
A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component.
Published 2026-09-03
- CriticalCVSS 9.8 v3·EPSS 0.4%·No fix yet
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
Published 2026-09-03
- HighCVSS 7.1 v3·EPSS 0.2%·No fix yet
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
Published 2026-09-03
- MediumCVSS 5.4 v3·EPSS 0.1%·No fix yet
Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or activity whose name matches an existing team; because the endpoints POST /api/customers/{id}/team, POST /api/projects/{id}/team, and POST /api/activities/{id}/team reuse an existing team of the same name and add the current user as teamlead without verifying that the user is authorized to manage that team, the attacker gains unauthorized team-lead (administration) rights over the existing team. Fixed in 2.65.0.
Published 2026-09-02
- HighCVSS 8.8 v3·EPSS 0.3%·No fix yet
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
Published 2026-09-02
- CriticalCVSS 9.8 v3·EPSS 0.3%·No fix yet
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
Published 2026-09-02
- HighCVSS 8.3 v3·EPSS 0.3%·No fix yet
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 is sufficient to fix this issue. It is recommended to upgrade the affected component.
Published 2026-09-01
- HighCVSS 7.5 v3·EPSS 0.3%·No fix yet
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Published 2026-08-31
Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.