Threats Tagged 'cwe-807'
View all threats tagged with 'cwe-807'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-807'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-54730: CWE-284: Improper Access Control in goauthentik authentikCVE-2026-54730 0 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome Device Trust Connector stage in an authentication flow. The device attestation occurs in a verification iframe that calls the Google Verified Access API and records the verified device on success, but the vulnerable stages treat the flow as passed as soon as the stage is submitted. An attacker who can reach such a stage, including after primary username and password authentication, can skip the verification iframe and authenticate from a device that was never verified. Where device trust is the only additional factor, that protection is fully bypassed, while other configured factors remain in force. This issue is fixed in versions 2026.2.6 and 2026.5.5. Join the discussion | CVE Database V5 | 08/18/2026, 16:55:29 UTC Added: 08/18/2026, 17:20:42 UTC |
CVE-2026-53789: CWE-807 Reliance on Untrusted Inputs in a Security Decision in RsyncProject rsyncCVE-2026-53789 0 rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory. Join the discussion | CVE Database V5 | 08/13/2026, 14:37:14 UTC Added: 08/13/2026, 15:12:04 UTC |
CVE-2026-64934: CWE-807 Reliance on untrusted inputs in a security decision in Quanovate Tech Inc. (operating as Mira / Mira Care) Mira FirmwareCVE-2026-64934 0 The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics. Join the discussion | CVE Database V5 | 08/11/2026, 21:15:13 UTC Added: 08/11/2026, 21:26:47 UTC |
CVE-2026-19579: CWE-639 Authorization bypass through User-Controlled key in Grokability Snipe-ITCVE-2026-19579 0 Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0. Join the discussion | CVE Database V5 | 08/11/2026, 20:25:02 UTC Added: 08/11/2026, 20:26:54 UTC |
CVE-2026-18705: CWE-807: Reliance on Untrusted Inputs in a Security Decision in MongoDB MongoDB ServerCVE-2026-18705 0 An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process. Join the discussion | CVE Database V5 | 08/11/2026, 18:37:54 UTC Added: 08/11/2026, 19:12:36 UTC |
CVE-2026-58239: CWE-807: Reliance on Untrusted Inputs in a Security Decision in SAP_SE SAP Business AI Platform (Approuter)CVE-2026-58239 0 SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability. Join the discussion | CVE Database V5 | 08/11/2026, 00:15:40 UTC Added: 08/11/2026, 00:42:04 UTC |
CVE-2026-9077: CWE-807 Reliance on Untrusted Inputs in a Security Decision in IBM Langflow OSSCVE-2026-9077 0 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. Join the discussion | CVE Database V5 | 08/05/2026, 16:24:43 UTC Added: 08/05/2026, 16:57:08 UTC |
CVE-2026-13059: CWE-807: Reliance on Untrusted Inputs in a Security Decision in MongoDB MongoDB ServerCVE-2026-13059 0 An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and aggregate commands in non-apiStrict configurations. Join the discussion | CVE Database V5 | 07/22/2026, 19:21:06 UTC Added: 07/22/2026, 20:07:58 UTC |
Showing 1 to 8 of 8 results