Articles tagged Access Control
-
VulnerabilityN-able N-central Access Control Flaw (CVE-2026-86206)
CVE-2026-86206 is an internal API access-control bypass in N-able N-central RMM software, per VulnCheck alone.
-
VulnerabilityOracle HTTP Server Access Control Flaw (CVE-2026-21962)
CVE-2026-21962 is a CVSS 10.0 access control flaw in Oracle HTTP Server and the WebLogic Proxy Plug-in, KEV-listed Aug. 24, 2026, EPSS at the 98th percentile.
-
Vulnerability2 CVEs: Azure AI Language & Milvus (CVE-2026-70352)
A VulnCheck KEV-listed Milvus flaw and a maximum CVSS 10.0 Azure AI Language elevation-of-privilege CVE, both single-sourced with minimal technical detail.
-
Vulnerability6 n8n CVEs (CVE-2026-86073)
Six n8n access-control CVEs: an OAuth consent-scope bypass, an approval-gate bypass, and four cross-user data-disclosure flaws.
-
VulnerabilityZ-BlogPHP Access Control Flaw (CVE-2026-8747)
CVE-2026-8747 is an improper authorization vulnerability in the comment-approval handler of Z-BlogPHP 1.7.4.3430, exploitable remotely with a public exploit.
-
VulnerabilityJeecgBoot Access Control Flaw (CVE-2026-86228)
CVE-2026-86228 is an improper access control vulnerability in JeecgBoot low-code platform, exploitable via the credential argument of an AI-model export function, fixed in version 3.9.5.