CWE-863
Allowed-with-ReviewIncorrect Authorization
Abstraction: Class · Status: Incomplete
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
6966 vulnerabilities reference this CWE, most recent first.
CVE-2026-105090 (GCVE-0-2026-105090)
Vulnerability from cvelistv5 – Published: 2026-10-03 01:59 – Updated: 2026-10-03 01:59- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/formbricks/formbricks/releases… | release-notespatch |
| https://github.com/formbricks/formbricks/releases… | release-notespatch |
| https://github.com/formbricks/formbricks/pull/9432 | patch |
| https://www.sec4check.pl/blog/posts/cve-formbrick… | technical-description |
| Vendor | Product | Version | |
|---|---|---|---|
| Formbricks | Formbricks |
Affected:
0 , < 5.4.4
(semver)
Affected: 6.0.0 , < 6.0.1 (semver) |
{
"containers": {
"cna": {
"affected": [
{
"collectionURL": "https://github.com/formbricks/formbricks",
"defaultStatus": "unaffected",
"product": "Formbricks",
"vendor": "Formbricks",
"versions": [
{
"lessThan": "5.4.4",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "6.0.1",
"status": "affected",
"version": "6.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T01:59:10.911Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "Formbricks release 6.0.1 (fix)",
"tags": [
"release-notes",
"patch"
],
"url": "https://github.com/formbricks/formbricks/releases/tag/6.0.1"
},
{
"name": "Formbricks release 5.4.4 (fix, backport)",
"tags": [
"release-notes",
"patch"
],
"url": "https://github.com/formbricks/formbricks/releases/tag/5.4.4"
},
{
"name": "PR #9432 - require Manage access to change survey custom head scripts",
"tags": [
"patch"
],
"url": "https://github.com/formbricks/formbricks/pull/9432"
},
{
"tags": [
"technical-description"
],
"url": "https://www.sec4check.pl/blog/posts/cve-formbricks-broken-access-control-stored-xss-custom-head-scripts.html"
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-105090",
"datePublished": "2026-10-03T01:59:10.911Z",
"dateReserved": "2026-10-03T01:59:10.142Z",
"dateUpdated": "2026-10-03T01:59:10.911Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104873 (GCVE-0-2026-104873)
Vulnerability from cvelistv5 – Published: 2026-10-02 20:06 – Updated: 2026-10-02 20:06- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/langchain-ai/langgraph/securit… | x_refsource_CONFIRM |
| https://github.com/langchain-ai/langgraph/commit/… | x_refsource_MISC |
| https://github.com/langchain-ai/langgraph/release… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| langchain-ai | langgraph |
Affected:
>= 0.1.45, < 0.4.4
|
{
"containers": {
"cna": {
"affected": [
{
"product": "langgraph",
"vendor": "langchain-ai",
"versions": [
{
"status": "affected",
"version": "\u003e= 0.1.45, \u003c 0.4.4"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, the langgraph-sdk resource-scoped authorization decorators @auth.on.threads, @auth.on.assistants, and @auth.on.crons ignore the actions argument and register the selected handler for every action on the resource. Because that wildcard resource handler is selected before broader fallback handlers, an authenticated user may bypass fallback action, ownership, or permission checks and read, update, or delete another user\u0027s resource. Only Python deployments using actions on the affected decorators are vulnerable, and a deployment remains protected when the selected handler independently enforces all required checks for every action it receives. This issue is fixed in version 0.4.4."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T20:06:07.090Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/langchain-ai/langgraph/security/advisories/GHSA-fvww-7h3r-vfhp",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/langchain-ai/langgraph/security/advisories/GHSA-fvww-7h3r-vfhp"
},
{
"name": "https://github.com/langchain-ai/langgraph/commit/5a77be5e8bec1600ad0a865638d88c1368497559",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/langchain-ai/langgraph/commit/5a77be5e8bec1600ad0a865638d88c1368497559"
},
{
"name": "https://github.com/langchain-ai/langgraph/releases/tag/sdk==0.4.4",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/langchain-ai/langgraph/releases/tag/sdk==0.4.4"
}
],
"source": {
"advisory": "GHSA-fvww-7h3r-vfhp",
"discovery": "UNKNOWN"
},
"title": "LangGraph SDK custom auth silently ignores actions= on resource decorators"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-104873",
"datePublished": "2026-10-02T20:06:07.090Z",
"dateReserved": "2026-10-02T14:59:11.775Z",
"dateUpdated": "2026-10-02T20:06:07.090Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104480 (GCVE-0-2026-104480)
Vulnerability from cvelistv5 – Published: 2026-10-02 00:57 – Updated: 2026-10-02 18:18| URL | Tags |
|---|---|
| https://github.com/discord/libdave/commit/9686fba… | patch |
| https://github.com/discord/libdave/releases/tag/v… | release-notes |
| https://daveprotocol.com/ | technical-description |
| https://github.com/discord/libdave | product |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104480",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T18:18:39.777597Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T18:18:52.157Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"modules": [
"C++ library"
],
"packageName": "discord/libdave",
"product": "libdave",
"programFiles": [
"cpp/src/mls/session.cpp"
],
"programRoutines": [
{
"name": "discord::dave::mls::Session::VerifyWelcomeState"
}
],
"repo": "https://github.com/discord/libdave",
"vendor": "Discord",
"versions": [
{
"lessThan": "1.2.0",
"status": "affected",
"version": "1.1.0",
"versionType": "semver"
},
{
"lessThan": "9686fbaea864aa19f0675e486672b6a77811b6a1",
"status": "affected",
"version": "7b15f1fc16f159da0478aa6be909e38f1e957833",
"versionType": "git"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "MDL (https://heartbreak.ing)"
}
],
"descriptions": [
{
"lang": "en",
"value": "Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-390",
"description": "CWE-390 Detection of Error Condition Without Action",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T00:57:55.648Z",
"orgId": "4ac701fe-44e9-4bcd-9585-dd6449257611",
"shortName": "Bugcrowd"
},
"references": [
{
"name": "[cpp] restore strict validation of MLS welcome state",
"tags": [
"patch"
],
"url": "https://github.com/discord/libdave/commit/9686fbaea864aa19f0675e486672b6a77811b6a1"
},
{
"name": "libdave v1.2.0 release notes",
"tags": [
"release-notes"
],
"url": "https://github.com/discord/libdave/releases/tag/v1.2.0/cpp"
},
{
"name": "Discord Audio and Video End-to-End Encryption (DAVE) Protocol Whitepaper",
"tags": [
"technical-description"
],
"url": "https://daveprotocol.com/"
},
{
"tags": [
"product"
],
"url": "https://github.com/discord/libdave"
}
],
"title": "Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "4ac701fe-44e9-4bcd-9585-dd6449257611",
"assignerShortName": "Bugcrowd",
"cveId": "CVE-2026-104480",
"datePublished": "2026-10-02T00:57:55.648Z",
"dateReserved": "2026-10-02T00:57:11.860Z",
"dateUpdated": "2026-10-02T18:18:52.157Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104443 (GCVE-0-2026-104443)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 13:32- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/YesWiki/yeswiki/security/advis… | vendor-advisory |
| https://www.vulncheck.com/advisories/yeswiki-befo… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104443",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T13:32:12.569494Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T13:32:37.738Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-9j7h-ccj2-jxv6"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "yeswiki",
"vendor": "YesWiki",
"versions": [
{
"lessThan": "4.6.7",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.6.7",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-09-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:17.722Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-9j7h-ccj2-jxv6)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-9j7h-ccj2-jxv6"
},
{
"name": "VulnCheck Advisory: YesWiki before 4.6.7 Scope Bypass via Triples Delete API",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-scope-bypass-via-triples-delete-api"
}
],
"title": "YesWiki before 4.6.7 Scope Bypass via Triples Delete API",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104443",
"datePublished": "2026-10-02T11:38:17.722Z",
"dateReserved": "2026-10-02T00:53:03.851Z",
"dateUpdated": "2026-10-02T13:32:37.738Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104054 (GCVE-0-2026-104054)
Vulnerability from cvelistv5 – Published: 2026-10-02 02:00 – Updated: 2026-10-02 19:52| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412762 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412762/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-104054 | third-party-advisory |
| https://vuldb.com/submit/959492 | third-party-advisory |
| https://github.com/calcom/cal.diy/issues/29802 | exploitissue-tracking |
| https://github.com/calcom/cal.diy/pull/30253 | issue-trackingpatch |
| https://github.com/calcom/cal.diy/ | product |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104054",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T19:52:33.884677Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T19:52:48.259Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:calcom:cal.diy:*:*:*:*:*:*:*:*"
],
"modules": [
"PBAC Permission Engine"
],
"product": "cal.diy",
"vendor": "calcom",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"status": "affected",
"version": "6.1"
},
{
"status": "affected",
"version": "6.2.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "geochen (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T02:00:11.876Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412762 | calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412762"
},
{
"name": "VDB-412762 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412762/cti"
},
{
"name": "CVE-2026-104054 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-104054"
},
{
"name": "Submit #959492 | https://github.com/calcom/ cal.diy commit 4026669 broken access control",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/959492"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/calcom/cal.diy/issues/29802"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/calcom/cal.diy/pull/30253"
},
{
"tags": [
"product"
],
"url": "https://github.com/calcom/cal.diy/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-01T20:02:21.000Z",
"value": "VulDB entry last update"
}
],
"title": "calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-104054",
"datePublished": "2026-10-02T02:00:11.876Z",
"dateReserved": "2026-10-01T17:57:14.224Z",
"dateUpdated": "2026-10-02T19:52:48.259Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103758 (GCVE-0-2026-103758)
Vulnerability from cvelistv5 – Published: 2026-10-01 10:42 – Updated: 2026-10-01 14:35- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/obot-platform/obot/security/ad… | vendor-advisory |
| https://www.vulncheck.com/advisories/obot-0.21.1-… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| obot-platform | obot |
Affected:
0.21.1 , ≤ 0.24.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103758",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:34:42.584937Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:35:10.239Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/obot-platform/obot",
"product": "obot",
"vendor": "obot-platform",
"versions": [
{
"lessThanOrEqual": "0.24.1",
"status": "affected",
"version": "0.21.1",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "arpitjain099"
}
],
"datePublic": "2026-09-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ route. Basic-role users with a composite MCP ID can proxy requests through mcpGateway.Proxy to invoke tools on MCP servers restricted by Access Control Rules."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T10:42:26.638Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-6fwv-3h4c-37j9)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/obot-platform/obot/security/advisories/GHSA-6fwv-3h4c-37j9"
},
{
"name": "VulnCheck Advisory: Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ Route",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/obot-0.21.1-through-0.24.1-authorization-bypass-via-mcp-connect-composite-route"
}
],
"title": "Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ Route",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103758",
"datePublished": "2026-10-01T10:42:26.638Z",
"dateReserved": "2026-10-01T10:39:47.844Z",
"dateUpdated": "2026-10-01T14:35:10.239Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103547 (GCVE-0-2026-103547)
Vulnerability from cvelistv5 – Published: 2026-09-30 19:40 – Updated: 2026-09-30 19:55- CWE-863 - Incorrect Authorization
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103547",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T19:55:41.738525Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T19:55:54.044Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "OpenBSD",
"repo": "https://github.com/openbsd/src",
"vendor": "OpenBSD",
"versions": [
{
"lessThan": "errata 057",
"status": "affected",
"version": "7.8",
"versionType": "custom"
},
{
"lessThan": "errata 021",
"status": "affected",
"version": "7.9",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*",
"versionEndExcluding": "errata 057",
"versionStartIncluding": "7.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*",
"versionEndExcluding": "errata 021",
"versionStartIncluding": "7.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)"
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T19:40:53.200Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://www.openbsd.org/errata79.html"
},
{
"url": "https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960"
},
{
"url": "https://ftp.openbsd.org/pub/OpenBSD/patches/7.9/common/021_ldapd.patch.sig"
},
{
"url": "https://www.openbsd.org/errata78.html"
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-103547",
"datePublished": "2026-09-30T19:40:53.200Z",
"dateReserved": "2026-09-30T19:40:52.241Z",
"dateUpdated": "2026-09-30T19:55:54.044Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103396 (GCVE-0-2026-103396)
Vulnerability from cvelistv5 – Published: 2026-09-30 14:48 – Updated: 2026-09-30 16:57- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/mlogclub/bbs-go/issues/303 | issue-tracking |
| https://github.com/mlogclub/bbs-go/commit/97d0bb3… | patch |
| https://github.com/mlogclub/bbs-go/blob/v4.4.6/in… | technical-description |
| https://github.com/mlogclub/bbs-go/blob/v4.4.6/in… | technical-description |
| https://github.com/mlogclub/bbs-go | product |
| https://www.vulncheck.com/advisories/bbs-go-throu… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103396",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:57:45.943159Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:57:55.383Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/mlogclub/bbs-go",
"product": "bbs-go",
"repo": "https://github.com/mlogclub/bbs-go",
"vendor": "mlogclub",
"versions": [
{
"lessThanOrEqual": "4.4.6",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bbs-go_project:bbs-go:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-09-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the synccount endpoint to trigger expensive full-table user recounts and cache invalidations, causing denial of service through repeated concurrent database operations."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:48:56.405Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #303",
"tags": [
"issue-tracking"
],
"url": "https://github.com/mlogclub/bbs-go/issues/303"
},
{
"tags": [
"patch"
],
"url": "https://github.com/mlogclub/bbs-go/commit/97d0bb3dcbacd686fd5300295afbf4f4a5da7609"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/mlogclub/bbs-go/blob/v4.4.6/internal/permissions/admin_permission_registry.go#L59-L60"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/mlogclub/bbs-go/blob/v4.4.6/internal/handlers/admin/user_handlers.go#L47-L59"
},
{
"tags": [
"product"
],
"url": "https://github.com/mlogclub/bbs-go"
},
{
"name": "VulnCheck Advisory: bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/bbs-go-through-4.4.6-incorrect-authorization-via-api-admin-user-synccount"
}
],
"title": "bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103396",
"datePublished": "2026-09-30T14:48:56.405Z",
"dateReserved": "2026-09-30T14:28:17.453Z",
"dateUpdated": "2026-09-30T16:57:55.383Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103284 (GCVE-0-2026-103284)
Vulnerability from cvelistv5 – Published: 2026-10-01 10:42 – Updated: 2026-10-01 13:31- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/TryGhost/Ghost/security/adviso… | vendor-advisory |
| https://www.vulncheck.com/advisories/ghost-5.125.… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103284",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:30:35.262552Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:31:23.254Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/ghost",
"product": "Ghost",
"vendor": "TryGhost",
"versions": [
{
"lessThan": "6.57.1",
"status": "affected",
"version": "5.125.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.57.1",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.57.1",
"versionStartIncluding": "5.125.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "default-cybe"
},
{
"lang": "en",
"type": "reporter",
"value": "doanmanhducz"
}
],
"datePublic": "2026-08-13T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T10:42:19.592Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-vm82-r49m-224q)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-vm82-r49m-224q"
},
{
"name": "VulnCheck Advisory: Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/ghost-5.125.1-before-6.57.1-information-disclosure-via-feedback"
}
],
"title": "Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103284",
"datePublished": "2026-10-01T10:42:19.592Z",
"dateReserved": "2026-09-30T10:59:26.443Z",
"dateUpdated": "2026-10-01T13:31:23.254Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103273 (GCVE-0-2026-103273)
Vulnerability from cvelistv5 – Published: 2026-10-01 10:42 – Updated: 2026-10-01 13:33- CWE-863 - Incorrect Authorization
| URL | Tags |
|---|---|
| https://github.com/TryGhost/Ghost/security/adviso… | vendor-advisory |
| https://www.vulncheck.com/advisories/ghost-4.3.0-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103273",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:33:41.482510Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:33:50.258Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/ghost",
"product": "Ghost",
"vendor": "TryGhost",
"versions": [
{
"lessThan": "6.58.0",
"status": "affected",
"version": "4.3.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.58.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.58.0",
"versionStartIncluding": "4.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-08-20T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T10:42:11.810Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-jj85-wvj2-r86m)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-jj85-wvj2-r86m"
},
{
"name": "VulnCheck Advisory: Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/ghost-4.3.0-before-6.58.0-incorrect-authorization-via-staff-token"
}
],
"title": "Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103273",
"datePublished": "2026-10-01T10:42:11.810Z",
"dateReserved": "2026-09-30T10:59:00.638Z",
"dateUpdated": "2026-10-01T13:33:50.258Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
- Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries.
- Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
Mitigation
Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Mitigation MIT-4.4
Strategy: Libraries or Frameworks
- Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
- For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
Mitigation
- For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page.
- One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages restrict access to requests that are accompanied by an active and authenticated session token associated with a user who has the required permissions to access that page.
Mitigation
Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a "default deny" policy when defining these ACLs.
No CAPEC attack patterns related to this CWE.