Authorization Bypass
Flaws where the identity is real but the permission check is not, and what that gets an attacker.
Published work on this topic
| 2026-08-17 | CVE-2026-56654 | CVE-2026-56654: Gitea - Access Token Scope Escalation | PoC | |
| 2026-08-11 | CVE-2026-59851 | CVE-2026-59851: libssh Authorization Bypass | PoC | |
| 2026-08-11 | CVE-2026-72585 | CVE-2026-72585: Grafana - Protected Receiver Auth Bypass | PoC | |
| 2026-08-09 | CVE-2026-71327 | CVE-2026-71327: Traefik - Route Identity Collision | PoC | |
| 2026-08-08 | CVE-2026-17594 | CVE-2026-17594: Nexus Privilege Escalation | PoC | |
| 2026-08-05 | CVE-2026-35210 | CVE-2026-35210: OpenCTI Authorization Bypass | PoC |
