Tag
#CWE-863
blogMEDIUM 6.3
Understanding and Defending Against CVE-2026-19350: A Missing Authorization Vulnerability in Dolibarr ERP
CVE-2026-19350 is a missing authorization vulnerability in the TakePOS module of Dolibarr ERP versions up to 23.0.3. This vulnerability allows remote attackers to perform unauthorized actions, potentially leading to data breaches or system compromise. The vulnerability has a CVSS score of 6.3 and is classified as CWE-862 and CWE-863.
blogHIGH 8.1
CVE-2026-68581: Vikunja API Token Management Vulnerability
CVE-2026-68581 is a high-severity vulnerability in Vikunja versions 0.22.0 through 2.3.0 that allows an authenticated attacker to manipulate API tokens of other users. The vulnerability has a CVSS score of 8.1 and is caused by a failure to validate the principal type in API token management. This vulnerability can lead to unauthorized access and control of user API tokens.