Tag

#Authorization Bypass

blogMEDIUM 6.5

Understanding and Defending Against CVE-2026-12973: Unauthorized Disclosure and Modification of WooCommerce Order Status

CVE-2026-12973 is a vulnerability in the PayPlus Payment Gateway WordPress plugin that allows unauthenticated users to disclose secret order keys and modify order statuses. This vulnerability has a CVSS score of 6.5 and is considered medium severity. It is not currently being actively exploited in the wild.

1 source
blogHIGH 7.1

Understanding and Defending Against Cross-Database IDOR in ArcadeDB

This educational analysis covers a critical vulnerability in ArcadeDB, a cross-database Insecure Direct Object Reference (IDOR) issue that allows unauthorized access to databases. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, detection strategies, and defensive measures.

1 source
articleHIGH 8.7

Critical Vulnerability in ArcadeDB: Unauthorized JavaScript Execution via SQL Injection

A critical vulnerability (GHSA-vwjc-v7x7-cm6g) has been discovered in ArcadeDB, a popular database management system. This vulnerability allows any user authorized for the database, including those with read-only roles, to bypass scripting authorization gates and execute arbitrary JavaScript code. The vulnerability has a CVSS score of 8.7 and can lead to severe impacts including SSRF, remote JavaScript inclusion, and unbounded CPU/memory DoS. Immediate patching to version 26.7.2 or later is highly recommended.

1 source
blogHIGH 7.5

Understanding and Defending Against CVE-2026-14165: Authorization Bypass in Tuleap Enterprise Edition

CVE-2026-14165 is an Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition versions 17.0 through 17.5. This vulnerability allows an attacker to access data of other users without authorization, posing a significant risk to the confidentiality of user data. The CVSS score for this vulnerability is 7.5, indicating a high severity. Understanding the root cause, attack surface, and exploitation mechanics is crucial for defenders to implement effective mitigations and detections.

1 source
articleHIGH 8.1

Critical Vulnerability in User Registration & Membership WordPress Plugin Allows Unauthorized Role Elevation

A high-severity vulnerability (CVE-2026-11963, CVSS 8.1) exists in the User Registration & Membership WordPress plugin prior to version 5.2.2. This flaw allows any authenticated user, including subscribers, to change another user's WordPress role and membership tier without proper authorization. The vulnerability has not been actively exploited but poses a significant risk due to its ease of exploitation and potential impact.

1 source
newsHIGH 8.0

CVE-2026-15293: WP Business Intelligence Lite Plugin Vulnerability

The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers with Subscriber-level access to modify stored SQL queries, potentially leading to privilege escalation. This affects all versions up to and including 3.2.0, with a CVSS score of 8.

1 source
blogHIGH 8.1

Understanding CVE-2026-22555: Unauthorized Repository Forking in Gitea

CVE-2026-22555 is a high-severity vulnerability in Gitea, a popular open-source Git server, that allows API users to fork a repository into an organization without proper authorization. This can lead to exposure of organization secrets. The vulnerability has a CVSS score of 8.1 and affects Gitea versions before 1.26.0.

1 source
blogHIGH 7.2

Understanding Cross-Tenant BOLA Vulnerability in stigmem-node

This educational analysis covers a critical vulnerability in stigmem-node, a multi-tenant node that mishandles RTBF tombstones, leading to cross-tenant BOLA (Broken Object Level Authorization). The vulnerability allows an attacker to mis-attribute and suppress reads tenant-blind, compromising data-view correctness and RTBF guarantees.

1 source
newsHIGH 8.1

praisonai-platform Vulnerability Allows Workspace Takeover

A vulnerability in praisonai-platform allows any member to remove any other member, including the workspace owner, enabling a full workspace takeover.

1 source