<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Security Misconfiguration (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/misconfiguration.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/misconfiguration-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Security Misconfiguration (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-40715 – Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40715</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40715</strong></p>
  <p>Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7198 – CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.862...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7198</guid>
    <pubDate>Tue, 02 Jun 2026 14:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7198</strong></p>
  <p>CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42670 – Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42670</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42670</strong></p>
  <p>Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42669 – Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42669</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42669</strong></p>
  <p>Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects EventPrime: from n/a through 4.3.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53345 – Missing Authorization vulnerability leading to code execution after installing m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53345</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53345</strong></p>
  <p>Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core.  This issue affects Thim Core: from n/a through 2.3.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9614 – An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9614</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9614</strong></p>
  <p>An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45281 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45281</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45281</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could possibly send a request to gain full access to their calendar. Therefore, the attacker must be an authenticated user. This is because of improper authorization controls in the backend…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8501 – Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8501</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8501</strong></p>
  <p>Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-782</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42677 – Missing Authorization vulnerability in Ben Balter WP Document Revisions allows E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42677</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42677</strong></p>
  <p>Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects WP Document Revisions: from n/a before 4.0.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42675 – Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42675</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42675</strong></p>
  <p>Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Hydra Booking: from n/a through 1.1.41.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42682 – Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42682</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42682</strong></p>
  <p>Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects wpForo Forum: from n/a through 3.0.6.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49198 – Improper access control in the MQTT broker allows wildcard topic subscriptions, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49198</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49198</strong></p>
  <p>Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10056 – CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10056</guid>
    <pubDate>Fri, 29 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10056</strong></p>
  <p>CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious cross-origin web page visited by the victim. The High security mode is not affect…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42071 – Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42071</guid>
    <pubDate>Thu, 28 May 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42071</strong></p>
  <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to download attachments on private bugnotes they should not be able to access, via the REST API endpoint GET /api/rest/issues/{id}/files and SOAP API mc_issue_attachment_get endpoint. This vulnerability…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31266 – Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31266</guid>
    <pubDate>Wed, 27 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31266</strong></p>
  <p>Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42753 – Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42753</guid>
    <pubDate>Wed, 27 May 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42753</strong></p>
  <p>Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9580 – A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9580</guid>
    <pubDate>Tue, 26 May 2026 21:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9580</strong></p>
  <p>A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is sufficient to fix this issue. It is suggested to upgrade…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14361 – Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14361</guid>
    <pubDate>Tue, 26 May 2026 21:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14361</strong></p>
  <p>Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs.  This issue affects Woocommerce Envato Affiliates: from n/a through 1.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9562 – A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9562</guid>
    <pubDate>Tue, 26 May 2026 17:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9562</strong></p>
  <p>A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensurin…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9517 – A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9517</guid>
    <pubDate>Tue, 26 May 2026 00:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9517</strong></p>
  <p>A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product impleme…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45438 – Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45438</guid>
    <pubDate>Mon, 25 May 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45438</strong></p>
  <p>Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45209 – Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45209</guid>
    <pubDate>Mon, 25 May 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45209</strong></p>
  <p>Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects MyCryptoCheckout: from n/a through 2.161.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9350 – A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9350</guid>
    <pubDate>Sun, 24 May 2026 04:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9350</strong></p>
  <p>A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py of the component Batch Runner. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9284 – The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthoriz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9284</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9284</strong></p>
  <p>The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order o…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6895 – The WishList Member plugin for WordPress is vulnerable to Missing Authorization ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6895</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6895</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can auth…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6419 – The WishList Member plugin for WordPress is vulnerable to Privilege Escalation v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6419</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6419</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to supply an arbitrary admin screen identifier via the data[url] paramete…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34908 – A malicious actor with access to the network could exploit an Improper Access Co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34908</guid>
    <pubDate>Fri, 22 May 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34908</strong></p>
  <p>A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8350 – Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8350</guid>
    <pubDate>Thu, 21 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8350</strong></p>
  <p>Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access to the bulk user assignment dashboard page can add any user email to any group and can remove legitimate admins. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with v…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42834 – Improper access control in Windows Admin Center allows an authorized attacker to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42834</guid>
    <pubDate>Wed, 20 May 2026 13:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42834</strong></p>
  <p>Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0856 – Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0856</guid>
    <pubDate>Wed, 20 May 2026 11:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0856</strong></p>
  <p>Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5200 – The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5200</guid>
    <pubDate>Wed, 20 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5200</strong></p>
  <p>The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify pri…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8495 – Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8495</guid>
    <pubDate>Tue, 19 May 2026 23:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8495</strong></p>
  <p>Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.  This issue affects Date iCal: from 0.0.0 before 4.0.15.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47100 – Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47100</guid>
    <pubDate>Tue, 19 May 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47100</strong></p>
  <p>Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkou…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2031 – An Improper Access Control vulnerability in several internal API endpoints for G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2031</guid>
    <pubDate>Fri, 15 May 2026 16:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2031</strong></p>
  <p>An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertently exposed internal API endpoints.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6510 – The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6510</guid>
    <pubDate>Thu, 14 May 2026 07:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6510</strong></p>
  <p>The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This makes it possible for unauthenticated attackers to create a malicious automation recipe that pairs an HTTP post trigger with an auto-login ac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6506 – The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6506</guid>
    <pubDate>Thu, 14 May 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6506</strong></p>
  <p>The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which user meta keys can be updated. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44380 – MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44380</guid>
    <pubDate>Wed, 13 May 2026 21:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44380</strong></p>
  <p>MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site administrator accounts within the same organization. Because non-site administrators were not explicitly prevented from accessing o…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44277 – A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, Fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44277</guid>
    <pubDate>Tue, 12 May 2026 18:17:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44277</strong></p>
  <p>A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42832 – Improper access control in Microsoft Office allows an unauthorized attacker to p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42832</guid>
    <pubDate>Tue, 12 May 2026 18:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42832</strong></p>
  <p>Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42823 – Improper access control in Azure Logic Apps allows an authorized attacker to ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42823</guid>
    <pubDate>Tue, 12 May 2026 18:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42823</strong></p>
  <p>Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41102 – Improper access control in Microsoft Office PowerPoint allows an authorized atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41102</guid>
    <pubDate>Tue, 12 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41102</strong></p>
  <p>Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41101 – Improper access control in Microsoft Office Word allows an authorized attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41101</guid>
    <pubDate>Tue, 12 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41101</strong></p>
  <p>Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41086 – Improper access control in Windows Admin Center allows an authorized attacker to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41086</guid>
    <pubDate>Tue, 12 May 2026 18:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41086</strong></p>
  <p>Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40381 – Improper access control in Azure Connected Machine Agent allows an authorized at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40381</guid>
    <pubDate>Tue, 12 May 2026 18:17:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40381</strong></p>
  <p>Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35438 – Missing authorization in Windows Admin Center allows an authorized attacker to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35438</guid>
    <pubDate>Tue, 12 May 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35438</strong></p>
  <p>Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33834 – Improper access control in Windows Event Logging Service allows an authorized at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33834</guid>
    <pubDate>Tue, 12 May 2026 18:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33834</strong></p>
  <p>Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26083 – A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26083</guid>
    <pubDate>Tue, 12 May 2026 18:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26083</strong></p>
  <p>A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 2…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20887 – Improper access control for some Intel Vision software for all versions within R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20887</guid>
    <pubDate>Tue, 12 May 2026 17:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20887</strong></p>
  <p>Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable remote code execution. This result may potentially occur via network access when attack requirements are not present without special internal knowledge a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39432 – Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Inco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39432</guid>
    <pubDate>Tue, 12 May 2026 09:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39432</strong></p>
  <p>Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Timetics: from n/a through 1.0.53.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45006 – OpenClaw before 2026.4.23 contains an improper access control vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45006</guid>
    <pubDate>Mon, 11 May 2026 18:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45006</strong></p>
  <p>OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration changes by bypassing an incomplete denylist protection. Attackers can persist malicious config modifications affecting command execution, network behavior, credentials, and operator policies that sur…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43639 – Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43639</guid>
    <pubDate>Mon, 11 May 2026 18:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43639</strong></p>
  <p>Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization; self-hosted installations are unaffected as this endpoint is restricted to Cloud via SelfHosted(NotSelfHostedOnly = true).</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32658 – Dell Automation Platform versions prior to 2.0.0.0, contains a missing authoriza...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32658</guid>
    <pubDate>Mon, 11 May 2026 10:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32658</strong></p>
  <p>Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42461 – Arcane is an interface for managing Docker containers, images, networks, and vol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42461</guid>
    <pubDate>Sat, 09 May 2026 04:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42461</strong></p>
  <p>Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/templates* in Arcane's Huma backend are registered without any Security requirement, allowing any unauthenticated network client to list and read the full Compose YAML and .env content of every custom template stored in the instance. Because Arcane's UI expo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42880 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42880</guid>
    <pubDate>Thu, 07 May 2026 23:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42880</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. T…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35435 – Improper access control in Azure AI Foundry M365 published agents allows an unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35435</guid>
    <pubDate>Thu, 07 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35435</strong></p>
  <p>Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33844 – Improper access control in Azure Managed Instance for Apache Cassandra allows an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33844</guid>
    <pubDate>Thu, 07 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33844</strong></p>
  <p>Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33109 – Improper access control in Azure Managed Instance for Apache Cassandra allows an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33109</guid>
    <pubDate>Thu, 07 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33109</strong></p>
  <p>Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5788 – An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5788</guid>
    <pubDate>Thu, 07 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5788</strong></p>
  <p>An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5786 – An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5786</guid>
    <pubDate>Thu, 07 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5786</strong></p>
  <p>An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42436 – OpenClaw before 2026.4.14 contains an improper access control vulnerability in b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42436</guid>
    <pubDate>Tue, 05 May 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42436</strong></p>
  <p>OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab routes that fail to consistently validate the final browser target after navigation. Authenticated callers can bypass SSRF restrictions to expose internal or disallowed page content by exploiting route-driven navigation without proper policy re-validation.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5294 – The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5294</guid>
    <pubDate>Tue, 05 May 2026 04:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5294</strong></p>
  <p>The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispatch and reaching a plugin installer helper that downloads and unzips attacker-supplied ZIP files into wp-content/plugins/. This makes it possible for unauthenticated attackers to perform arbitrary plu…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7468 – A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7468</guid>
    <pubDate>Thu, 30 Apr 2026 01:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7468</strong></p>
  <p>A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue r…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5141 – Improper Privilege Management, Improper Access Control, Incorrect privilege assi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5141</guid>
    <pubDate>Wed, 29 Apr 2026 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5141</strong></p>
  <p>Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking a privileged process.  This issue affects Pardus Software Center: from 1.0.2 before 1.0.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42515 – This vulnerability exists in e-Sushrut due to improper access control in resourc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42515</guid>
    <pubDate>Wed, 29 Apr 2026 09:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42515</strong></p>
  <p>This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API request URL to gain unauthorized access to sensitive information of patients on the targeted system.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42377 – Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42377</guid>
    <pubDate>Wed, 29 Apr 2026 08:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42377</strong></p>
  <p>Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects SureForms Pro: from n/a through 2.8.0.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24222 – NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initializati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24222</guid>
    <pubDate>Tue, 28 Apr 2026 19:36:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24222</strong></p>
  <p>NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5944 – An improper access control vulnerability exists in the Cisco Intersight Device C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5944</guid>
    <pubDate>Tue, 28 Apr 2026 14:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5944</strong></p>
  <p>An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication.    An unauthenticated attacker with network access can exploit this vulnerability by sending crafted requests to the exp…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6741 – The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6741</guid>
    <pubDate>Mon, 27 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6741</strong></p>
  <p>The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authorization check in the execute() method of the connect-customer-to-wp-user ability, which only requires the customer__edit capability granted to the latepoint_agent role by default, without verifying whet…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33318 – Actual is a local-first personal finance tool. Prior to version 26.4.0, any auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33318</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33318</strong></p>
  <p>Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three weaknesses combine: `POST /account/change-password` has no authorization check, allowing any session to overwrite the password hash; the inactive password `auth` row is never remove…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40630 – A vulnerability in 
SenseLive 

X3050’s web management interface allows unauthor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40630</guid>
    <pubDate>Fri, 24 Apr 2026 00:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40630</strong></p>
  <p>A vulnerability in  SenseLive   X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network access to the device may be able to bypass the intended authentication mechanism and directly interact with sensitive configuration functions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24303 – Improper access control in Microsoft Partner Center allows an authorized attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24303</guid>
    <pubDate>Thu, 23 Apr 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24303</strong></p>
  <p>Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6376 – A weakness in SpiceJet’s public booking retrieval page permits full passenger bo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6376</guid>
    <pubDate>Thu, 23 Apr 2026 21:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6376</strong></p>
  <p>A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no authentication or verification mechanisms. This results in exposure of extensive personal, travel, and booking metadata to any unauthenticated user who can obtain or guess those basic inputs. The issue arises from improper access control on a sensiti…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6375 – A vulnerability in SpiceJet’s booking API allows unauthenticated users to query ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6375</guid>
    <pubDate>Thu, 23 Apr 2026 21:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6375</strong></p>
  <p>A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing authorization checks on an endpoint intended for authenticated profile access.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41454 – WeKan before 8.35 contains a missing authorization vulnerability in the Integrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41454</guid>
    <pubDate>Wed, 22 Apr 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41454</strong></p>
  <p>WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insuffici…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41039 – This vulnerability exists in Quantum Networks router due to improper access cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41039</guid>
    <pubDate>Tue, 21 Apr 2026 11:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41039</strong></p>
  <p>This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration in the web-based management interface. An unauthenticated attacker could exploit this vulnerability by accessing exposed API endpoints on the targeted device.  Successful exploitation of this vulnerability could allow the attacker to access sensitive information, including intern…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30269 – Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30269</guid>
    <pubDate>Mon, 20 Apr 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30269</strong></p>
  <p>Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update model without a manage_users permission check for self-updates, enabling privilege escalation to high-privileged roles.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6372 – Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6372</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6372</strong></p>
  <p>Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept Cryptocurrencies with Plisio: from n/a through 2.0.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27914 – Improper access control in Microsoft Management Console allows an authorized att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27914</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27914</strong></p>
  <p>Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26183 – Improper access control in Windows RPC API allows an authorized attacker to elev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26183</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26183</strong></p>
  <p>Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34256 – Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34256</guid>
    <pubDate>Tue, 14 Apr 2026 01:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34256</strong></p>
  <p>Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular ABAP report to overwrite any existing eight?character executable ABAP report without authorization. If the overwritten report is subsequently executed, the intended functionality could become unavailable. Successful exploitation impacts availability,…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22566 – An Improper Access Control vulnerability could allow a malicious actor with acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22566</guid>
    <pubDate>Mon, 13 Apr 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22566</strong></p>
  <p>An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials.    Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)  UniFi Play Audio Port  (Version 1.0.24 and earlier)    Mitigation: Update UniFi Play PowerAmp to Version 1.0.38 or later  Update UniFi Play Audio Port  to Version 1.1.9 or later</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22564 – An Improper Access Control vulnerability could allow a malicious actor with acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22564</guid>
    <pubDate>Mon, 13 Apr 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22564</strong></p>
  <p>An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.    Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)  UniFi Play Audio Port  (Version 1.0.24 and earlier)    Mitigation: Update UniFi Play PowerAmp to Version 1.0.38 or later  Update UniFi Play Audio Port  to Versi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40185 – TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authori...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40185</guid>
    <pubDate>Fri, 10 Apr 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40185</strong></p>
  <p>TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo management routes. This vulnerability is fixed in 2.7.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4162 – The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4162</guid>
    <pubDate>Fri, 10 Apr 2026 10:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4162</strong></p>
  <p>The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to uninstall and deactivate the plugin and delete plugin options. NOTE: This vulnerability i…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34512 – OpenClaw before 2026.3.25 contains an improper access control vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34512</guid>
    <pubDate>Thu, 09 Apr 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34512</strong></p>
  <p>OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated user to invoke admin-level session termination functions without proper scope validation. Attackers can exploit this by sending authenticated requests to kill arbitrary subagent sessions via the killSubagentRunAdmin function, bypassing owner…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33785 – A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33785</guid>
    <pubDate>Thu, 09 Apr 2026 22:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33785</strong></p>
  <p>A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices.  Any user logged in, without requiring specific privileges, can issue 'request csds' CLI operational commands. These commands are only meant to be executed by high…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62188 – An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62188</guid>
    <pubDate>Thu, 09 Apr 2026 10:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62188</strong></p>
  <p>An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.  This vulnerability may allow unauthorized actors to access sensitive information, including database credentials.   This issue affects Apache DolphinScheduler versions 3.1.*.   Users are recommended to upgrade to:          *  version ≥ 3.2.0 if using 3.1.x       As a temporary workaroun…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4326 – The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4326</guid>
    <pubDate>Thu, 09 Apr 2026 02:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4326</strong></p>
  <p>The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability check does not terminate execution when it fails — it only sets an error message variable while allowing…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5173 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5173</guid>
    <pubDate>Wed, 08 Apr 2026 23:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5173</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22682 – OpenHarness prior to commit 166fcfe contains an improper access control vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22682</guid>
    <pubDate>Tue, 07 Apr 2026 18:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22682</strong></p>
  <p>OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling in permission enforcement, allowing attackers who can influence agent tool execution to read arbitrary local files outside the intended repository scope. Attackers can exploit the path parameter not being passed to the PermissionChecker in read_file,…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22683 – Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22683</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22683</strong></p>
  <p>Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not enforce the Operator restriction on workspace endpoints, allowing an Operator to crea…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1114 – In parisneo/lollms version 2.1.0, the application's session management is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1114</guid>
    <pubDate>Tue, 07 Apr 2026 07:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1114</strong></p>
  <p>In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an attacker to perform an offline brute-force attack to recover the secret key. Once the secret key is obtained, the attacker can forge administrative tokens by modifying the JWT payload and…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35182 – Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35182</guid>
    <pubDate>Mon, 06 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35182</strong></p>
  <p>Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to change account roles and promote themselves to Super Admin. This vulnerability is fixed in 2.0.6.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5569 – A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5569</guid>
    <pubDate>Sun, 05 Apr 2026 14:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5569</strong></p>
  <p>A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been made public and could be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but d…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5526 – A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5526</guid>
    <pubDate>Sat, 04 Apr 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5526</strong></p>
  <p>A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35616 – A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35616</guid>
    <pubDate>Sat, 04 Apr 2026 01:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35616</strong></p>
  <p>A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22663 – prompts.chat prior to commit 7b81836 contains multiple authorization bypass vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22663</guid>
    <pubDate>Fri, 03 Apr 2026 21:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22663</strong></p>
  <p>prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that allow unauthorized users to access sensitive data associated with private prompts. Attackers can exploit these missing authorization checks to retrieve private prompt version history, change requests, examples, current c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30689 – A blog.admin v.8.0 and before system's getinfobytoken API interface contains an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30689</guid>
    <pubDate>Fri, 27 Mar 2026 15:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30689</strong></p>
  <p>A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34053 – OpenEMR is a free and open source electronic health records and medical practice...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34053</guid>
    <pubDate>Thu, 26 Mar 2026 00:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34053</strong></p>
  <p>OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any authenticated user, regardless of role, to irreversibly delete procedure orders, answers, and specimens belonging to any patient in the system. Versio…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32546 – Missing Authorization vulnerability in StellarWP Restrict Content restrict-conte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32546</guid>
    <pubDate>Wed, 25 Mar 2026 17:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32546</strong></p>
  <p>Missing Authorization vulnerability in StellarWP Restrict Content restrict-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Content: from n/a through <= 3.2.22.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32546">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
