Search Results (2946 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-91182 1 Open Business Management 1 Open Business Management 2026-10-04 3.3 Low
A flaw was found in open-cluster-management. An agent communicating via the gRPC broker can bypass authorization by manipulating the `ce-clustername` cloud event header attribute, which is used for authorization, independently of the actual event payload. This allows a registered managed cluster to gain unauthorized access, enabling it to move itself into other tenants' ManagedClusterSets and overwrite other clusters' ManagedCluster objects in the hub. The primary consequence is a breach of isolation between managed clusters, leading to unauthorized modification of cluster resources. This can lead to unauthorized receipt of newly delivered tenant workloads, policies, and secrets via Placement decisions. Additionally, an attacker can arbitrarily overwrite other clusters' ManagedCluster objects on the hub or perform unauthorized writes inside another cluster's dedicated hub namespace, such as forging Lease liveness heartbeats to manipulate availability status.
CVE-2026-94432 2 Latepoint, Wordpress-extensions 2 Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress, Appointment Booking Plugin 2026-10-03 5.3 Medium
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through wp_ajax_nopriv_latepoint_route_call. The handler loads an OsInvoiceModel by a sequential integer 'invoice_id' with no access-key/UUID or ownership check (the sibling Stripe and Razorpay handlers require a 128-bit access-key UUID via OsInvoicesHelper::get_invoice_by_key), and then calls OsTransactionIntentHelper::create_or_update_transaction_intent() which persists a transaction intent tied to the target invoice's customer_id, order_id and charge_amount and regenerates its intent_key before the PayPal-configured guard is reached. This makes it possible for unauthenticated attackers to enumerate invoices belonging to arbitrary customers, create unauthorized transaction-intent rows linked to another customer's data, and overwrite the intent_key of any in-flight NEW-status transaction intent — invalidating the intent_key that legitimate Stripe/Razorpay flows are waiting on and breaking payment webhooks for those customers.
CVE-2026-93882 2 Thimpress, Wordpress-extensions 2 Learnpress – Wordpress Lms Plugin For Create And Sell Online Courses, Learnpress 2026-10-03 7.5 High
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and performs no capability check, and the render_material_items() handler decides authorization against one attacker-supplied identifier (course_id) while fetching the returned material rows via a second, independently attacker-supplied identifier (item_id) with no check that the lesson belongs to the authorized course. This makes it possible for unauthenticated attackers to read and download course-material files (uploaded and external file paths/URLs) belonging to lessons in paid or enrollment-required courses, provided any single course on the site has 'No Required Enroll' enabled and owns at least one material file.
CVE-2026-91109 2 Croixhaug, Wordpress-extensions 2 Simply Schedule Appointments, Simply Schedule Appointments 2026-10-03 6.5 Medium
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose every co-booker's private per-appointment id_token (exposed as public_token) alongside their PII (name and email address), then use each leaked token to read, overwrite arbitrary appointment meta on, or cancel the co-booker's appointment via the same REST controller. Exploitation requires the attacker to possess a valid id_token for any single appointment within the targeted group booking.
CVE-2026-11399 2026-10-03 4.3 Medium
The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary ticket responses belonging to other users by supplying any stsw_responses row ID to the deletion handler after obtaining the nonce from the admin footer.
CVE-2026-104444 1 Yeswiki 1 Yeswiki 2026-10-02 7.1 High
YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.
CVE-2026-75101 1 Github 1 Enterprise Server 2026-10-02 6.5 Medium
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and pull request number rather than to a globally unique repository identifier, so an attacker who created a repository and pull request matching a target's repository name and pull request number could use a token for their own repository to retrieve the private pull request's contents. Exploitation required the attacker to know the target repository's name and a valid pull request number. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.21, 3.18.15, 3.19.12, 3.20.8, and 3.21.6. This vulnerability was reported via the GitHub Bug Bounty program.
CVE-2026-39444 2026-10-02 5.4 Medium
Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a through 3.1.3.
CVE-2026-79654 1 Redhat 3 Satellite, Satellite Capsule, Satellite Utils 2026-10-02 4.3 Medium
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.
CVE-2026-100272 1 Jetbrains 1 Youtrack 2026-10-02 4.9 Medium
In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
CVE-2026-85615 1 Openpanel 1 Openpanel 2026-10-02 6.4 Medium
Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply an arbitrary victim dashboardId with their own projectId to read report layouts and configurations or delete dashboard grid arrangements across tenants.
CVE-2026-85611 1 Openpanel 1 Openpanel 2026-10-02 6.4 Medium
OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable dashboardId to read confidential report definitions or permanently delete dashboard layouts across tenant boundaries.
CVE-2026-102876 1 Surrealdb 1 Surrealdb 2026-10-02 8.1 High
SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries.
CVE-2026-104449 1 Yeswiki 1 Yeswiki 2026-10-02 6.5 Medium
YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing page, overwriting its body for mass defacement and content destruction.
CVE-2026-51878 1 Hkuds 1 Deeptutor 2026-10-01 N/A
deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigger regenerate on another user's session.
CVE-2026-100514 2026-10-01 7.5 High
Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
CVE-2026-64948 1 Pandora Fms 1 Pandora Fms 2026-10-01 N/A
Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
CVE-2026-103247 1 N8n 1 N8n 2026-10-01 8.5 High
n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.
CVE-2026-62061 2 Metagauss, Wordpress-extensions 2 Profilegrid, Profilegrid 2026-10-01 5.3 Medium
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2.
CVE-2026-97269 2 Getwpfunnels, Wordpress-extensions 2 Wpfunnels, Wpfunnels 2026-10-01 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.