Threats Tagged 'cwe-863'
View all threats tagged with 'cwe-863'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-863'
Click on any threat for detailed analysis and mitigation recommendations
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a share ID when any share_users row exists for the caller, without requiring ShareUserStatus.Accepted. A low-privileged authenticated user with a pending folder-share invitation can create an item under the share ID, and ShareModel.updateSharedItems3() propagates the injected content to the owner and accepted participants before the attacker accepts the invitation. This issue is fixed in version 3.7.7. Join the discussion | CVE Database V5 | 09/21/2026, 21:15:15 UTC Added: 09/21/2026, 21:32:20 UTC |
Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy when a private-channel client is allowed presence.write but explicitly denied presence.read. Under that differential policy, the client can receive presence_diff messages containing other members' presence metadata, including application-defined location, online-status, roster, viewing, or typing information. Deployments with uniform presence visibility have no differential, and postgres_changes row data is unaffected. This issue is fixed in version 2.111.2. Join the discussion | CVE Database V5 | 09/21/2026, 19:04:58 UTC Added: 09/21/2026, 19:32:11 UTC |
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken without enforcing the owning user's allowed_ip_ranges against the trusted client address in warpgate-protocol-http/src/common.rs. An attacker holding a leaked, phished, or exfiltrated X-Warpgate-Token can therefore use it from a prohibited network location. Deployments without allowed_ip_ranges are unaffected, and HTTP target proxying plus SSH, MySQL, PostgreSQL, RDP, VNC, and Kubernetes paths do not accept this vulnerable HTTP token flow. This issue is fixed in version 0.27.3. Join the discussion | CVE Database V5 | 09/21/2026, 18:50:40 UTC Added: 09/21/2026, 19:02:22 UTC |
0 Tinyauth versions prior to 5.1.2 have a vulnerability where case-sensitive hostname comparisons allow authenticated low-privilege users to bypass per-application access controls by using differently cased hostnames. This occurs because reverse proxies route hostnames case-insensitively, but Tinyauth does not, leading to missed access control lookups and permissive access. Unauthenticated users and global login allowlists are not bypassed. The issue is fixed in version 5.1.2. Join the discussion | CVE Database V5 | 09/21/2026, 16:39:18 UTC Added: 09/21/2026, 22:12:11 UTC |
Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_tests.yml uses pull_request_target with the synchronize event and preserves ok-to-test, approved, or lgtm labels across newly pushed commits, allowing a fork contributor to obtain approval for a benign revision and then run changed code from refs/pull/${{ github.event.pull_request.number }}/merge through privileged make targets. The job exposes GCP, AWS, and Snowflake credentials to that code, enabling runner code execution, credential disclosure, and possible access to downstream cloud resources. An external label-removal integration could mitigate the condition, but no repository workflow provided that protection. This issue is fixed in version 0.65.0. Join the discussion | CVE Database V5 | 09/21/2026, 15:51:06 UTC Added: 09/21/2026, 16:02:29 UTC |
0 Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and branch identifiers to ListSatisfiedEntries without a tenant filter, allowing an authenticated tenant worker that knows another tenant's durable-task UUID to retrieve matching durable event-log records. The UUIDv4 requirement makes exploitation unlikely, and single-tenant deployments are unaffected in practice. This issue is fixed in version 0.106.1. Join the discussion | CVE Database V5 | 09/21/2026, 15:49:12 UTC Added: 09/21/2026, 16:02:29 UTC |
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-task} endpoint implemented by listDurableEventLog without requiring the target tenant as a parent resource, allowing an authenticated user who obtains another tenant's durable task UUID to read that task's event log. Disclosed data can include task display names, workflow identifiers, user messages, wait conditions, branching logic, and timing information. This issue is fixed in version 0.91.1. Join the discussion | CVE Database V5 | 09/21/2026, 15:44:07 UTC Added: 09/21/2026, 16:02:29 UTC |
The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass authorization checks and create arbitrary posts. Join the discussion | CVE Database V5 | 09/19/2026, 07:43:14 UTC Added: 09/19/2026, 07:47:14 UTC |
The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to. Join the discussion | CVE Database V5 | 09/19/2026, 06:00:17 UTC Added: 09/19/2026, 06:32:09 UTC |
IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. Join the discussion | CVE Database V5 | 09/18/2026, 19:04:02 UTC Added: 09/18/2026, 19:32:25 UTC |
Showing 1 to 10 of 997 results