CWE-863
Allowed-with-ReviewIncorrect Authorization
Abstraction: Class · Status: Incomplete
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
6993 vulnerabilities reference this CWE, most recent first.
CVE-2026-97335 (GCVE-0-2026-97335)
Vulnerability from cvelistv5 – Published: 2026-09-28 13:22 – Updated: 2026-09-28 16:32- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/canonical/lxd/security/advisor… | vendor-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97335",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T14:02:18.270198Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:32:28.403Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageName": "LXD",
"platforms": [
"Linux"
],
"product": "LXD",
"repo": "https://github.com/canonical/lxd",
"vendor": "Canonical",
"versions": [
{
"lessThan": "5.0.10",
"status": "affected",
"version": "5.0.0",
"versionType": "semver"
},
{
"lessThan": "5.21.8",
"status": "affected",
"version": "5.21.0",
"versionType": "semver"
},
{
"lessThan": "6.10",
"status": "affected",
"version": "6.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-25T03:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type."
}
],
"impacts": [
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-122 Privilege Abuse"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:22:19.371Z",
"orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"shortName": "canonical"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/canonical/lxd/security/advisories/GHSA-p456-92fx-44xh"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Incorrect authorization in LXD storage volume API allows reading volumes from other projects"
}
},
"cveMetadata": {
"assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
"assignerShortName": "canonical",
"cveId": "CVE-2026-97335",
"datePublished": "2026-09-28T13:22:19.371Z",
"dateReserved": "2026-09-24T12:15:00.374Z",
"dateUpdated": "2026-09-28T16:32:28.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96680 (GCVE-0-2026-96680)
Vulnerability from cvelistv5 – Published: 2026-09-23 23:00 – Updated: 2026-09-24 13:13| URL | Tags |
|---|---|
| https://vuldb.com/vuln/409003 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/409003/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-96680 | third-party-advisory |
| https://vuldb.com/submit/904123 | third-party-advisory |
| https://github.com/xryj920/chrome_extensions/blob… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| ByteDance | Coze Scraper Extension |
Affected:
2.0.0
Affected: 2.0.1 Affected: 2.0.2 cpe:2.3:a:bytedance:coze_scraper_extension:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96680",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T13:12:54.037634Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T13:13:38.289Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:bytedance:coze_scraper_extension:*:*:*:*:*:*:*:*"
],
"modules": [
"External Message Handler"
],
"product": "Coze Scraper Extension",
"vendor": "ByteDance",
"versions": [
{
"status": "affected",
"version": "2.0.0"
},
{
"status": "affected",
"version": "2.0.1"
},
{
"status": "affected",
"version": "2.0.2"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "DRXYJ-01 (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of the component External Message Handler. The manipulation of the argument body.url/paginationConfig/xPathConfig/body.urls/xPaths results in missing authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T23:00:11.989Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-409003 | ByteDance Coze Scraper Extension External Message index.js chrome.runtime.onMessageExternal.addListener authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/409003"
},
{
"name": "VDB-409003 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/409003/cti"
},
{
"name": "CVE-2026-96680 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-96680"
},
{
"name": "Submit #904123 | ByteDance Coze Scraper Chrome extension 2.0.2 Information Disclosure",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/904123"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/xryj920/chrome_extensions/blob/main/Coze%20Scraper%202.0.2%20Unrestricted%20External%20Message%20Handler%20Allows%20Website-Triggered%20Arbitrary%20URL%20Scraping"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-23T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-23T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-23T17:43:21.000Z",
"value": "VulDB entry last update"
}
],
"title": "ByteDance Coze Scraper Extension External Message index.js chrome.runtime.onMessageExternal.addListener authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-96680",
"datePublished": "2026-09-23T23:00:11.989Z",
"dateReserved": "2026-09-23T15:38:11.433Z",
"dateUpdated": "2026-09-24T13:13:38.289Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96603 (GCVE-0-2026-96603)
Vulnerability from cvelistv5 – Published: 2026-09-23 21:45 – Updated: 2026-09-24 13:14| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408969 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/408969/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-96603 | third-party-advisory |
| https://vuldb.com/submit/899001 | third-party-advisory |
| https://github.com/yashkeral/cve-writeups/blob/ma… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| Abdurrab5 | online-makeup-store |
Affected:
336a4b09e5c840bdfe6dfde6616add0b20e4b4ee
Affected: c3ca96769c008a8a1518c8f9adbc7c8b52d83480 Affected: f804fe3ef5cf3570ced0fa34fb2de492a1306345 cpe:2.3:a:abdurrab5:online-makeup-store:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96603",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T13:14:13.081408Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T13:14:20.360Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:abdurrab5:online-makeup-store:*:*:*:*:*:*:*:*"
],
"modules": [
"Admin Handler"
],
"product": "online-makeup-store",
"vendor": "Abdurrab5",
"versions": [
{
"status": "affected",
"version": "336a4b09e5c840bdfe6dfde6616add0b20e4b4ee"
},
{
"status": "affected",
"version": "c3ca96769c008a8a1518c8f9adbc7c8b52d83480"
},
{
"status": "affected",
"version": "f804fe3ef5cf3570ced0fa34fb2de492a1306345"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Yashkumar Keral (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of the argument adminid leads to missing authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T21:45:07.022Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408969 | Abdurrab5 online-makeup-store Admin functions.php confirm_user authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/408969"
},
{
"name": "VDB-408969 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408969/cti"
},
{
"name": "CVE-2026-96603 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-96603"
},
{
"name": "Submit #899001 | Abdurrab5 (Github) Online Makeup Store 1.0 Missing Authorization (Broken Access Control)",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/899001"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/yashkeral/cve-writeups/blob/main/online-makeup-store/03-broken-access-control.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-23T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-23T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-23T15:52:50.000Z",
"value": "VulDB entry last update"
}
],
"title": "Abdurrab5 online-makeup-store Admin functions.php confirm_user authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-96603",
"datePublished": "2026-09-23T21:45:07.022Z",
"dateReserved": "2026-09-23T13:46:30.114Z",
"dateUpdated": "2026-09-24T13:14:20.360Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96512 (GCVE-0-2026-96512)
Vulnerability from cvelistv5 – Published: 2026-09-23 13:22 – Updated: 2026-10-05 10:23- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:71609 | vendor-advisoryx_refsource_REDHAT |
| https://access.redhat.com/errata/RHSA-2026:75571 | vendor-advisoryx_refsource_REDHAT |
| https://access.redhat.com/errata/RHSA-2026:75579 | vendor-advisoryx_refsource_REDHAT |
| https://access.redhat.com/errata/RHSA-2026:75580 | vendor-advisoryx_refsource_REDHAT |
| https://access.redhat.com/security/cve/CVE-2026-96512 | vdb-entryx_refsource_REDHAT |
| https://bugzilla.redhat.com/show_bug.cgi?id=2539327 | issue-trackingx_refsource_REDHAT |
| https://github.com/sudo-project/sudo/commit/1820a… | |
| http://www.openwall.com/lists/oss-security/2026/09/24/4 |
| Vendor | Product | Version | |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 |
Unaffected:
0:1.9.17-10.p2.el10_2.7 , < *
(rpm)
cpe:/o:redhat:enterprise_linux:10.2 |
|
| Red Hat | Red Hat Enterprise Linux 8 |
Unaffected:
0:1.9.5p2-2.el8_10 , < *
(rpm)
cpe:/o:redhat:enterprise_linux:8::baseos |
|
| Red Hat | Red Hat Enterprise Linux 9 |
Unaffected:
0:1.9.17p2-3.el9_8.3 , < *
(rpm)
cpe:/a:redhat:enterprise_linux:9::appstream cpe:/o:redhat:enterprise_linux:9::baseos |
|
| Red Hat | Red Hat Hardened Images |
Unaffected:
1.9.17-16.p2.2.hum1 , < *
(rpm)
cpe:/a:redhat:hummingbird:1 |
|
| Red Hat | Red Hat Enterprise Linux 7 |
cpe:/o:redhat:enterprise_linux:7
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96512",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T03:55:22.775Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2026-09-24T18:09:32.796Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/24/4"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:10.2"
],
"defaultStatus": "affected",
"packageName": "sudo",
"product": "Red Hat Enterprise Linux 10",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:1.9.17-10.p2.el10_2.7",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:8::baseos"
],
"defaultStatus": "affected",
"packageName": "sudo",
"product": "Red Hat Enterprise Linux 8",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:1.9.5p2-2.el8_10",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:9::appstream",
"cpe:/o:redhat:enterprise_linux:9::baseos"
],
"defaultStatus": "affected",
"packageName": "sudo",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:1.9.17p2-3.el9_8.3",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:enterprise_linux:9::appstream",
"cpe:/o:redhat:enterprise_linux:9::baseos"
],
"defaultStatus": "affected",
"packageName": "sudo",
"product": "Red Hat Enterprise Linux 9",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "0:1.9.17p2-3.el9_8.3",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://catalog.redhat.com/software/containers/",
"cpes": [
"cpe:/a:redhat:hummingbird:1"
],
"defaultStatus": "affected",
"packageName": "sudo-main",
"product": "Red Hat Hardened Images",
"vendor": "Red Hat",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "1.9.17-16.p2.2.hum1",
"versionType": "rpm"
}
]
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"defaultStatus": "affected",
"packageName": "sudo",
"product": "Red Hat Enterprise Linux 7",
"vendor": "Red Hat"
}
],
"credits": [
{
"lang": "en",
"value": "Upstream acknowledges Ermenson Junior (Independent security research) as the original reporter."
}
],
"datePublic": "2026-09-23T12:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing \u0027Z\u0027 timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Important"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-05T10:23:18.705Z",
"orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"shortName": "redhat"
},
"references": [
{
"name": "RHSA-2026:71609",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:71609"
},
{
"name": "RHSA-2026:75571",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:75571"
},
{
"name": "RHSA-2026:75579",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:75579"
},
{
"name": "RHSA-2026:75580",
"tags": [
"vendor-advisory",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/errata/RHSA-2026:75580"
},
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-96512"
},
{
"name": "RHBZ#2539327",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539327"
},
{
"url": "https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-08-28T00:00:00.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-09-23T12:00:00.000Z",
"value": "Made public."
}
],
"title": "Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization",
"workarounds": [
{
"lang": "en",
"value": "Append the \u0027Z\u0027 timezone suffix to all NOTBEFORE and NOTAFTER timestamps in sudoers rules. For example, change \u0027NOTAFTER=20261231235959\u0027 to \u0027NOTAFTER=20261231235959Z\u0027. Timestamps with the \u0027Z\u0027 suffix are interpreted as UTC via timegm() and are not affected by the TZ environment variable. Administrators can audit their sudoers configuration with: grep -rE \u0027NOT(BEFORE|AFTER)=\u0027 /etc/sudoers /etc/sudoers.d/ and verify that all timestamps end with \u0027Z\u0027."
}
],
"x_generator": {
"engine": "cvelib 1.8.0"
},
"x_redhatCweChain": "CWE-863: Incorrect Authorization"
}
},
"cveMetadata": {
"assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"assignerShortName": "redhat",
"cveId": "CVE-2026-96512",
"datePublished": "2026-09-23T13:22:33.080Z",
"dateReserved": "2026-09-23T10:31:55.548Z",
"dateUpdated": "2026-10-05T10:23:18.705Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95814 (GCVE-0-2026-95814)
Vulnerability from cvelistv5 – Published: 2026-09-22 20:21 – Updated: 2026-09-23 12:51- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/dani-garcia/vaultwarden/pull/7554 | patchissue-tracking |
| https://github.com/dani-garcia/vaultwarden/blob/1… | technical-description |
| https://github.com/dani-garcia/vaultwarden/blob/1… | technical-description |
| https://github.com/dani-garcia/vaultwarden | product |
| https://www.vulncheck.com/advisories/vaultwarden-… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| dani-garcia | vaultwarden |
Affected:
0 , ≤ 1.37.3
(semver)
cpe:2.3:a:dani-garcia:vaultwarden:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95814",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T12:49:15.557025Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T12:51:17.228Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://github.com/dani-garcia/vaultwarden",
"defaultStatus": "unaffected",
"packageURL": "pkg:github/dani-garcia/vaultwarden",
"product": "vaultwarden",
"repo": "https://github.com/dani-garcia/vaultwarden",
"vendor": "dani-garcia",
"versions": [
{
"lessThanOrEqual": "1.37.3",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:dani-garcia:vaultwarden:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.37.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Siyang Wu"
}
],
"datePublic": "2026-08-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status filters in get_user_collections_access_flags, get_group_collections_access_flags, and is_in_full_access_group to access protected cipher data server-side."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T20:21:13.488Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #7554 (open, unmerged)",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/dani-garcia/vaultwarden/pull/7554"
},
{
"name": "Cipher::get_access_restrictions at 1.37.3",
"tags": [
"technical-description"
],
"url": "https://github.com/dani-garcia/vaultwarden/blob/1.37.3/src/db/models/cipher.rs"
},
{
"name": "Group::is_in_full_access_group at 1.37.3",
"tags": [
"technical-description"
],
"url": "https://github.com/dani-garcia/vaultwarden/blob/1.37.3/src/db/models/group.rs"
},
{
"tags": [
"product"
],
"url": "https://github.com/dani-garcia/vaultwarden"
},
{
"name": "VulnCheck Advisory: Vaultwarden through 1.37.3 Authorization Bypass via Missing Status Check",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/vaultwarden-through-1.37.3-authorization-bypass-via-missing-status-check"
}
],
"title": "Vaultwarden through 1.37.3 Authorization Bypass via Missing Status Check",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-95814",
"datePublished": "2026-09-22T20:21:13.488Z",
"dateReserved": "2026-09-22T15:47:13.821Z",
"dateUpdated": "2026-09-23T12:51:17.228Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95811 (GCVE-0-2026-95811)
Vulnerability from cvelistv5 – Published: 2026-09-25 01:31 – Updated: 2026-09-26 15:07| URL | Tags |
|---|---|
| https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/… | issue-tracking |
| https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/… | release-notes |
| https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/… | release-notes |
| https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/… | release-notes |
| https://www.cve.org/CVERecord?id=CVE-2020-24660 | related |
| https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/… | exploit |
| https://lists.debian.org/debian-lts-announce/2026… |
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-95811",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T13:53:01.823535Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T13:53:07.656Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3723"
}
],
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2026-09-26T15:07:03.342Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://lists.debian.org/debian-lts-announce/2026/09/msg00032.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"modules": [
"Lemonldap::NG::Handler"
],
"packageName": "Lemonldap-NG-Handler",
"packageURL": "pkg:cpan/Lemonldap-NG-Handler",
"programFiles": [
"lib/Lemonldap/NG/Handler/Main/Run.pm"
],
"programRoutines": [
{
"name": "Lemonldap::NG::Handler::Main::Run::run"
},
{
"name": "Lemonldap::NG::Handler::Main::Run::grant"
},
{
"name": "Lemonldap::NG::Handler::Main::Run::getLevel"
},
{
"name": "Lemonldap::NG::Handler::Main::Run::isUnprotected"
}
],
"repo": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng",
"versions": [
{
"lessThan": "2.16.10",
"status": "affected",
"version": "2.0.0",
"versionType": "custom"
},
{
"lessThan": "2.21.6",
"status": "affected",
"version": "2.17.0",
"versionType": "custom"
},
{
"lessThan": "2.23.4",
"status": "affected",
"version": "2.22.0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Deepseek agent, Linagora"
}
],
"descriptions": [
{
"lang": "en",
"value": "Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it.\n\nThe handler matches each vhost\u0027s locationRules regular expressions against REQUEST_URI, the raw request line, while the web server routes on the path it has already percent-decoded and normalized. A request that percent-encodes a character of the path, inserts dot segments, or doubles a slash therefore reaches the protected resource under a URI that no rule regexp matches, and the vhost\u0027s default rule decides access. Deny rules, identity and group conditions, and unprotect and skip rules are bypassed alike.\n\nOnly a vhost whose default rule is more permissive than its other rules is affected. An authenticated user then reaches any URL a locationRules regexp was meant to restrict, but gains no more than that default rule already grants."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-180",
"description": "CWE-180 Incorrect Behavior Order: Validate Before Canonicalize",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T01:31:22.472Z",
"orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"shortName": "CPANSec"
},
"references": [
{
"tags": [
"issue-tracking"
],
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3723"
},
{
"tags": [
"release-notes"
],
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4"
},
{
"tags": [
"release-notes"
],
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6"
},
{
"tags": [
"release-notes"
],
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.16.10"
},
{
"tags": [
"related"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2020-24660"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to Lemonldap-NG-Handler 2.16.10, 2.21.6 or 2.23.4 or later. Only 2.23.4 is on CPAN; the 2.16.10 and 2.21.6 LTS releases are available from https://lemonldap-ng.org/download.html."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it",
"x_generator": {
"engine": "cpansec-cna-tool 0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"assignerShortName": "CPANSec",
"cveId": "CVE-2026-95811",
"datePublished": "2026-09-25T01:31:22.472Z",
"dateReserved": "2026-09-22T15:43:06.362Z",
"dateUpdated": "2026-09-26T15:07:03.342Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95654 (GCVE-0-2026-95654)
Vulnerability from cvelistv5 – Published: 2026-09-22 15:24 – Updated: 2026-09-22 15:48- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/David-Crty/databasement/commit… | patch |
| https://github.com/David-Crty/databasement/blob/v… | technical-description |
| https://github.com/David-Crty/databasement/blob/v… | technical-description |
| https://github.com/David-Crty/databasement/releas… | release-notes |
| https://github.com/David-Crty/databasement | product |
| https://www.vulncheck.com/advisories/databasement… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| David-Crty | Databasement |
Affected:
0 , < 1.7.14
(semver)
Unaffected: 1.7.14 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95654",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:48:26.638426Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:48:52.843Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Databasement",
"vendor": "David-Crty",
"versions": [
{
"lessThan": "1.7.14",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.7.14",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Abror Bakhromov"
}
],
"datePublic": "2026-09-07T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can load the page while pending, then accept the invitation after the legitimate user has already accepted it to overwrite the account password and gain authenticated access to managed database credentials and secrets."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:24:12.859Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/David-Crty/databasement/commit/128efeaf6bc9ad4a63940f4c3030a56ab2969778"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/David-Crty/databasement/blob/v1.7.13/app/Livewire/Auth/AcceptInvitation.php#L30"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/David-Crty/databasement/blob/v1.7.13/app/Livewire/Auth/AcceptInvitation.php#L45"
},
{
"name": "Databasement v1.7.14 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/David-Crty/databasement/releases/tag/v1.7.14"
},
{
"tags": [
"product"
],
"url": "https://github.com/David-Crty/databasement"
},
{
"name": "VulnCheck Advisory: Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/databasement-before-1.7.14-authorization-bypass-via-stale-invitation-token"
}
],
"title": "Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-95654",
"datePublished": "2026-09-22T15:24:12.859Z",
"dateReserved": "2026-09-22T12:28:58.960Z",
"dateUpdated": "2026-09-22T15:48:52.843Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94609 (GCVE-0-2026-94609)
Vulnerability from cvelistv5 – Published: 2026-09-24 16:20 – Updated: 2026-09-28 15:41| Vendor | Product | Version | |
|---|---|---|---|
| goauthentik | authentik |
Affected:
< 2026.2.7
Affected: >= 2026.5.0, < 2026.5.7 Affected: >= 2026.8.0, < 2026.8.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94609",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T15:41:43.925095Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T15:41:52.662Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "authentik",
"vendor": "goauthentik",
"versions": [
{
"status": "affected",
"version": "\u003c 2026.2.7"
},
{
"status": "affected",
"version": "\u003e= 2026.5.0, \u003c 2026.5.7"
},
{
"status": "affected",
"version": "\u003e= 2026.8.0, \u003c 2026.8.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deployments that delegate these management capabilities to accounts that are not full administrators are affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269: Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T16:20:45.703Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/goauthentik/authentik/security/advisories/GHSA-h6c5-mpvq-j4jc",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/goauthentik/authentik/security/advisories/GHSA-h6c5-mpvq-j4jc"
},
{
"name": "https://github.com/goauthentik/authentik/pull/25956",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/pull/25956"
},
{
"name": "https://github.com/goauthentik/authentik/pull/25961",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/pull/25961"
},
{
"name": "https://github.com/goauthentik/authentik/pull/25966",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/pull/25966"
},
{
"name": "https://github.com/goauthentik/authentik/pull/25971",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/pull/25971"
},
{
"name": "https://github.com/goauthentik/authentik/commit/5f95b86f6f70c3bd8c625a4f9ae474e235f84030",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/commit/5f95b86f6f70c3bd8c625a4f9ae474e235f84030"
},
{
"name": "https://github.com/goauthentik/authentik/commit/67317f66f1b7eb16f2a26bf550dfd73699d49d87",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/commit/67317f66f1b7eb16f2a26bf550dfd73699d49d87"
},
{
"name": "https://github.com/goauthentik/authentik/commit/67e470dde8c81a40ee27ec6e178462368c561a60",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/commit/67e470dde8c81a40ee27ec6e178462368c561a60"
},
{
"name": "https://github.com/goauthentik/authentik/commit/898e4e4fa070642a3541a376af0de64fe3ffeb67",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/commit/898e4e4fa070642a3541a376af0de64fe3ffeb67"
},
{
"name": "https://docs.goauthentik.io/releases/2026.2#fixed-in-202627",
"tags": [
"x_refsource_MISC"
],
"url": "https://docs.goauthentik.io/releases/2026.2#fixed-in-202627"
},
{
"name": "https://docs.goauthentik.io/releases/2026.5#fixed-in-202657",
"tags": [
"x_refsource_MISC"
],
"url": "https://docs.goauthentik.io/releases/2026.5#fixed-in-202657"
},
{
"name": "https://docs.goauthentik.io/releases/2026.8#fixed-in-202682",
"tags": [
"x_refsource_MISC"
],
"url": "https://docs.goauthentik.io/releases/2026.8#fixed-in-202682"
},
{
"name": "https://github.com/goauthentik/authentik/releases/tag/version/2026.2.7",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/releases/tag/version/2026.2.7"
},
{
"name": "https://github.com/goauthentik/authentik/releases/tag/version/2026.5.7",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/releases/tag/version/2026.5.7"
},
{
"name": "https://github.com/goauthentik/authentik/releases/tag/version/2026.8.2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/goauthentik/authentik/releases/tag/version/2026.8.2"
}
],
"source": {
"advisory": "GHSA-h6c5-mpvq-j4jc",
"discovery": "UNKNOWN"
},
"title": "authentik: Privilege Escalation to Superuser via Group Hierarchy"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-94609",
"datePublished": "2026-09-24T16:20:45.703Z",
"dateReserved": "2026-09-21T21:32:23.741Z",
"dateUpdated": "2026-09-28T15:41:52.662Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93954 (GCVE-0-2026-93954)
Vulnerability from cvelistv5 – Published: 2026-09-19 21:45 – Updated: 2026-09-22 15:43 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/407913 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/407913/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-93954 | third-party-advisory |
| https://vuldb.com/submit/943919 | third-party-advisory |
| https://github.com/grimmory-tools/grimmory/issues/2430 | exploitissue-tracking |
| https://github.com/grimmory-tools/grimmory/pull/2647 | issue-trackingpatch |
| https://github.com/grimmory-tools/grimmory/commit… | patch |
| https://github.com/grimmory-tools/grimmory/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| grimmory-tools | grimmory |
Affected:
3.3.0
Affected: 3.3.1 Affected: 3.3.2 Affected: 3.3.3 Affected: 3.4.0 Affected: 3.4.1 cpe:2.3:a:grimmory-tools:grimmory:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93954",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:30:23.928893Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:43:56.136Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:grimmory-tools:grimmory:*:*:*:*:*:*:*:*"
],
"modules": [
"Settings API Endpoint"
],
"product": "grimmory",
"vendor": "grimmory-tools",
"versions": [
{
"status": "affected",
"version": "3.3.0"
},
{
"status": "affected",
"version": "3.3.1"
},
{
"status": "affected",
"version": "3.3.2"
},
{
"status": "affected",
"version": "3.3.3"
},
{
"status": "affected",
"version": "3.4.0"
},
{
"status": "affected",
"version": "3.4.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "summmm (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 2b66ca6df8110f6b512e030b54c16b9fbe318f17. Applying a patch is advised to resolve this issue. PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-19T21:45:11.207Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-407913 | grimmory-tools grimmory Settings API Endpoint AppSettingController.java AppSettingController.getAppSettings authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/407913"
},
{
"name": "VDB-407913 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/407913/cti"
},
{
"name": "CVE-2026-93954 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-93954"
},
{
"name": "Submit #943919 | grimmory-tools grimmory 3.3.3 Incorrect Access Control",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/943919"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/grimmory-tools/grimmory/issues/2430"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/grimmory-tools/grimmory/pull/2647"
},
{
"tags": [
"patch"
],
"url": "https://github.com/grimmory-tools/grimmory/commit/2b66ca6df8110f6b512e030b54c16b9fbe318f17"
},
{
"tags": [
"product"
],
"url": "https://github.com/grimmory-tools/grimmory/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-19T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-19T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-19T10:56:23.000Z",
"value": "VulDB entry last update"
}
],
"title": "grimmory-tools grimmory Settings API Endpoint AppSettingController.java AppSettingController.getAppSettings authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-93954",
"datePublished": "2026-09-19T21:45:11.207Z",
"dateReserved": "2026-09-19T08:51:12.177Z",
"dateUpdated": "2026-09-22T15:43:56.136Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93643 (GCVE-0-2026-93643)
Vulnerability from cvelistv5 – Published: 2026-09-25 13:57 – Updated: 2026-09-26 03:55| URL | Tags |
|---|---|
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite (ZCS) |
Affected:
0 , < 10.1.21
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93643",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T03:55:49.487Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Zimbra Collaboration Suite (ZCS)",
"vendor": "Zimbra",
"versions": [
{
"lessThan": "10.1.21",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jonah Burgess (CryptoCat), Senior Security Researcher, Rapid7"
}
],
"datePublic": "2026-09-25T13:53:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned\u0026nbsp;\u003ccode\u003esave\u003c/code\u003e\u0026nbsp;fields to perform path-traversal writes and execute commands as\u0026nbsp;\u003ccode\u003ezimbra\u003c/code\u003e."
}
],
"value": "When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned\u00a0save\u00a0fields to perform path-traversal writes and execute commands as\u00a0zimbra."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T13:57:19.199Z",
"orgId": "9974b330-7714-4307-a722-5648477acda7",
"shortName": "rapid7"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "9974b330-7714-4307-a722-5648477acda7",
"assignerShortName": "rapid7",
"cveId": "CVE-2026-93643",
"datePublished": "2026-09-25T13:57:19.199Z",
"dateReserved": "2026-09-18T12:22:38.559Z",
"dateUpdated": "2026-09-26T03:55:49.487Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
- Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries.
- Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
Mitigation
Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Mitigation MIT-4.4
Strategy: Libraries or Frameworks
- Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
- For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
Mitigation
- For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page.
- One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages restrict access to requests that are accompanied by an active and authenticated session token associated with a user who has the required permissions to access that page.
Mitigation
Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a "default deny" policy when defining these ACLs.
No CAPEC attack patterns related to this CWE.