Search Results (13510 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-63464 1 Forgekeep 1 Nebula-mesh 2026-09-08 7.7 High
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-subscriptions). No admin check exists on this field. At delivery time, allow_private switches the dispatcher to an unguarded HTTP client, bypassing the private/loopback/link-local SSRF guard — letting a low-privilege operator make the server request internal addresses. This issue has been patched in version 0.7.2.
CVE-2026-77108 2026-09-08 7.5 High
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.
CVE-2026-77111 2026-09-08 8.7 High
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-84327 1 Google 2 Android, Chrome 2026-09-08 6.5 Medium
Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-70178 1 Microsoft 2 Fabric, Microsoft Fabric 2026-09-08 8.5 High
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
CVE-2026-16941 1 Ibm 1 I 2026-09-08 4.3 Medium
IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
CVE-2026-86274 1 Projeto-siga 1 Siga 2026-09-08 5.3 Medium
A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication Flow. Such manipulation of the argument cod/jwt leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-73014 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more 2026-09-08 7.8 High
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.
CVE-2026-69465 1 Microsoft 1 Sharepoint Server 2026-09-08 8.8 High
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-72966 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-09-08 5.5 Medium
Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.
CVE-2026-69453 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-09-08 5.5 Medium
Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
CVE-2026-83942 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-09-08 7.8 High
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-69724 1 Microsoft 1 Sharepoint Server 2026-09-08 8.8 High
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69641 1 Microsoft 3 Exchange Server 2016, Exchange Server 2019, Exchange Server Se 2026-09-08 9.1 Critical
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69380 1 Microsoft 3 Exchange Server 2016, Exchange Server 2019, Exchange Server Se 2026-09-08 8.1 High
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69553 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-09-08 7.1 High
Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.
CVE-2026-69377 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-09-08 7.8 High
Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
CVE-2026-83941 1 Microsoft 1 Microsoft Entra Id 2026-09-08 9.9 Critical
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
CVE-2026-86073 2026-09-08 N/A
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked only that the requested resource was registered, not that it matched the original grant. An OAuth client approved for one workflow could substitute a different workflow URL in the resource parameter and obtain a valid token for an unapproved workflow accessible to the consenting user. This issue is fixed in versions 2.37.7 and 2.38.1.
CVE-2026-78583 1 Elastic 1 Kibana 2026-09-08 8.1 High
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.