Tag

#Missing Authorization

newsCRITICAL 9.9

Critical Vulnerability in Ivanti Neurons for ITSM: CVE-2026-12647

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before version 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server, with a CVSS score of 9.9. Immediate action is required to update to the patched version.

1 source
articleCRITICAL 9.9

Critical Missing Authorization Vulnerability in Ivanti Neurons for ITSM

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before version 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. This vulnerability has a CVSS score of 9.9, indicating a critical severity. Although not actively exploited, the vulnerability's impact is significant, and immediate patching is recommended.

1 source
blogMEDIUM 6.3

Understanding and Defending Against CVE-2026-19350: A Missing Authorization Vulnerability in Dolibarr ERP

CVE-2026-19350 is a missing authorization vulnerability in the TakePOS module of Dolibarr ERP versions up to 23.0.3. This vulnerability allows remote attackers to perform unauthorized actions, potentially leading to data breaches or system compromise. The vulnerability has a CVSS score of 6.3 and is classified as CWE-862 and CWE-863.

1 source
articleHIGH 8.6

Critical Vulnerability in SiYuan Note-Taking Application Allows Unauthorized Content Disclosure (CVE-2026-68586)

A critical vulnerability (CVE-2026-68586) with a CVSS score of 8.6 affects the SiYuan note-taking application before version 3.7.3. The vulnerability allows a publish-mode reader, including anonymous readers, to retrieve rendered DOM content of publish-forbidden documents and determine if a document references a given block. Immediate patching to version 3.7.3 or later is recommended.

1 source
articleHIGH 7.6

MCP Python SDK Vulnerability: Experimental Task Handlers Allow Unauthorized Access to Tasks

A high-severity vulnerability (CVE-2026-52870) exists in the MCP Python SDK, specifically in the experimental tasks feature. When enabled, default request handlers do not check session ownership, allowing any client to access and cancel other clients' tasks. Affected versions are from 1.23.0 to 1.27.1. The vulnerability has a CVSS v3 score of 7.6 and is classified under CWE-862 (Missing Authorization).

1 source
articleHIGH 7.8

CVE-2026-6509: Missing Authorization in TUBITAK BILGEM Pardus Update Leads to Privilege Escalation

A Missing Authorization vulnerability, CVE-2026-6509, with a CVSS score of 7.8, was discovered in TUBITAK BILGEM Software Technologies Research Institute's Pardus Update. This vulnerability allows for Privilege Escalation and affects versions up to 0.6.3 before 0.6.6. Although not actively exploited, the vulnerability poses a high risk due to its local attack vector and potential for high impact. Immediate patching to version 0.6.6 or later is recommended.

1 source
articleHIGH 8.8

Critical Missing Authorization Vulnerability in TUBITAK BILGEM pardus-software

A critical Missing Authorization vulnerability, CVE-2026-14460, with a CVSS score of 8.8, was discovered in TUBITAK BILGEM's pardus-software. This vulnerability allows for Argument Injection and affects versions <= 1.0.4 before 1.0.5. Although not actively exploited, the vulnerability poses a high risk due to its local attack vector and potential for high impact. Immediate patching to version 1.0.5 is recommended.

1 source
newsHIGH 8.8

CVE-2026-56396: phpMyFAQ Privilege Escalation Vulnerability

A vulnerability in phpMyFAQ before version 4.1.4 allows authenticated administrators to escalate privileges due to missing authorization in the editUser() and updateUserRights() endpoints. Non-SuperAdmin users with edit_user permission can exploit this to gain SuperAdmin access. The vulnerability has a CVSS score of 8.8.

1 source