Incorrect Authorization

CWE-863 · 17 records · 12 with a public proof-of-concept

Records the NVD classes as Incorrect Authorization (CWE-863), highest CVSS first.

  1. HIGH 8.1CVE-2026-70494public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to perm

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-71234public PoC

    Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0), w

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-62927public PoC

    In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it wit

    milo

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-71247public PoC

    Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on fie

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.3CVE-2026-70490public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message JWT and never applied the verified-user r

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.3CVE-2026-18773public PoC

    A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The att

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5CVE-2026-71201

    In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 4.3CVE-2026-70488public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request b

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 4.3CVE-2026-70484public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permiss

    AI risk analysis on Exploit-DB.ai →

  10. UNSCOREDCVE-2026-71192

    In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own

    AI risk analysis on Exploit-DB.ai →

  11. UNSCOREDCVE-2026-71191

    In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causin

    AI risk analysis on Exploit-DB.ai →

  12. UNSCOREDCVE-2026-55707

    In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and

    AI risk analysis on Exploit-DB.ai →

  13. UNSCOREDCVE-2026-70474public PoC

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refr

    AI risk analysis on Exploit-DB.ai →

  14. UNSCOREDCVE-2026-70472public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that c

    AI risk analysis on Exploit-DB.ai →

  15. UNSCOREDCVE-2026-70471public PoC

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variab

    AI risk analysis on Exploit-DB.ai →

  16. UNSCOREDCVE-2026-69262public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was su

    AI risk analysis on Exploit-DB.ai →

  17. UNSCOREDCVE-2026-64630

    A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.

    AI risk analysis on Exploit-DB.ai →