Total
9771 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66379 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| An authenticated user may view private Puppet module metadata without repository read access. | ||||
| CVE-2026-66380 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | ||||
| CVE-2026-68753 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 5.3 Medium |
| An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | ||||
| CVE-2026-68754 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 6.5 Medium |
| A repository publisher without delete permission may modify protected package content under specific conditions. | ||||
| CVE-2026-68758 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 6.5 Medium |
| A low-privileged authenticated user may access restricted support information under specific conditions. | ||||
| CVE-2026-81269 | 1 Drupal | 1 Data Field | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. | ||||
| CVE-2026-81166 | 1 Drupal | 1 Digital Signage Framework | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. | ||||
| CVE-2026-18544 | 1 Ibm | 1 Portieris | 2026-09-02 | 8.1 High |
| IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references. | ||||
| CVE-2026-78597 | 1 Elastic | 1 Kibana | 2026-09-02 | 4.3 Medium |
| Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an administrative operation that creates and persists Elasticsearch API keys under the caller's identity, bypassing the elevated cluster and Kibana privileges that the documented Entity Store setup flow requires. | ||||
| CVE-2026-78607 | 1 Elastic | 1 Elasticsearch | 2026-09-02 | 5.4 Medium |
| Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed. | ||||
| CVE-2026-82394 | 1 Sulu | 1 Sulu | 2026-09-02 | N/A |
| Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforce VIEW permission for the target resource in PreviewLinkManager::generate() or PreviewLinkManager::revoke(). An authenticated administration user who knows a target resource identifier can create or revoke a preview link for any page, article, or snippet, including content in a webspace or area the user cannot view. A generated preview URL is public and resolves content by an opaque token, allowing the user or anyone receiving the link to read restricted content without authentication. This issue is fixed in versions 2.6.25 and 3.0.8. | ||||
| CVE-2026-84715 | 1 Mythicalltd | 1 Featherpanel | 2026-09-02 | 8.8 High |
| FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration. | ||||
| CVE-2026-14357 | 2 Dplugins, Wordpress | 2 Devkit Pro, Wordpress | 2026-09-02 | 8.8 High |
| The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary theme ZIP packages containing PHP files that are extracted into the web-accessible wp-content/themes/ directory, which may make remote code execution possible. | ||||
| CVE-2026-84835 | 2 Dimafreund, Wordpress | 2 Rentsyst, Wordpress | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2. | ||||
| CVE-2026-84801 | 1 Craftcms | 1 Craft Cms | 2026-09-02 | 8.8 High |
| Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via actionSetPassword, which validates only the verification code without checking the caller's session, enabling complete control-panel takeover. | ||||
| CVE-2026-84798 | 1 Craftcms | 1 Craft Cms | 2026-09-02 | 7.1 High |
| Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs the deletion authorization check against the user's own provisional draft (which only verifies draft ownership), then propagates the deletion to the canonical element without re-checking permissions. As a result, an authenticated user who has viewEntries, viewPeerEntries, saveEntries, savePeerEntries, and editSite permissions but lacks the deleteEntriesForSite permission can hard-delete a canonical entry's site record (and, for single-site entries, the full element and content), which is irrecoverable via Craft's recycle bin. | ||||
| CVE-2026-82871 | 1 Tooljet | 1 Tooljet | 2026-09-02 | 7.7 High |
| ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations. | ||||
| CVE-2026-82223 | 2 Arraytics, Wordpress | 2 Wp Event Solution, Wordpress | 2026-09-02 | 6.5 Medium |
| Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions. | ||||
| CVE-2026-82882 | 1 Devtron | 1 Devtron | 2026-09-02 | 8.8 High |
| Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control. | ||||
| CVE-2026-79745 | 1 Samanhappy | 1 Mcphub | 2026-09-02 | 7.1 High |
| MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, the built-in prompt and resource controllers perform no role checking. The mutating POST/PUT /api/prompts* and POST/PUT /api/resources* routes are attached to the authenticated router with no admin gate, and the handlers never read req.user. The DAO singletons they write are consulted first — ahead of any connected MCP server — for every session in handleGetPromptRequest / handleReadResourceRequest. A non-admin can therefore create, overwrite, and shadow global prompt templates and resources that all other users are served. The scored impact is the unauthorized integrity violation (creation/tampering/shadowing of globally-served records); stored prompt injection into other users' LLM sessions is a downstream consequence of that tampering. This issue has been patched in version 1.0.32. | ||||