PULSE
LIVE57signals / 24h
FEED
ransomthegentlemen reclama a DHC · JP · Not Foundransomthegentlemen reclama a INKA Group GmbH Co · DE · Manufacturingransomthegentlemen reclama a Vitex Pharmaceuticals · Healthcareransomthegentlemen reclama a Mdj Management · Otherransomthegentlemen reclama a Hst · US · Not Foundransomthegentlemen reclama a Groupe BPCE · VN · Financial Servicesransomthegentlemen reclama a Axson Teknik · SE · Manufacturingransomthegentlemen reclama a Ponti · PL · Otherransomthegentlemen reclama a Godollo · HU · Agriculture and Food Productionransomthegentlemen reclama a Hoang Chiropractic Center · US · Healthcareransomthegentlemen reclama a aZaaS · US · Technologyransomthegentlemen reclama a National Furniture Outlet · US · Retail & E-Commerceransomthegentlemen reclama a TESI · IT · Not Foundransomthegentlemen reclama a Intranet Gov Brasil · BR · Government & Defenseransomthegentlemen reclama a DHC · JP · Not Foundransomthegentlemen reclama a INKA Group GmbH Co · DE · Manufacturingransomthegentlemen reclama a Vitex Pharmaceuticals · Healthcareransomthegentlemen reclama a Mdj Management · Otherransomthegentlemen reclama a Hst · US · Not Foundransomthegentlemen reclama a Groupe BPCE · VN · Financial Servicesransomthegentlemen reclama a Axson Teknik · SE · Manufacturingransomthegentlemen reclama a Ponti · PL · Otherransomthegentlemen reclama a Godollo · HU · Agriculture and Food Productionransomthegentlemen reclama a Hoang Chiropractic Center · US · Healthcareransomthegentlemen reclama a aZaaS · US · Technologyransomthegentlemen reclama a National Furniture Outlet · US · Retail & E-Commerceransomthegentlemen reclama a TESI · IT · Not Foundransomthegentlemen reclama a Intranet Gov Brasil · BR · Government & Defense
← All CVEs
CVE WatchAug 7, 2026

CVE-2026-62830

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

CVSS

9.9

Critical

EPSS

KEV

Exploit Today

0-100

Published: Aug 7, 2026 · Last modified: Aug 7, 2026 · CWE-862

EPSS · 30d

Not enough EPSS history yet.

Technical description

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-143659.8 CRI
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.5h
CVE-2026-119076.5 MED
The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access all Stream activity records via the Heartbeat API.5h
CVE-2026-6566710.0 CRI
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.8h
CVE-2026-706367.5 HIG
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to bypass all authentication and authorization checks, triggering unauthorized OAuth token rotation against credentials belonging to any workspace and potentially disrupting dependent OAuth integrations. This is a bypass of CVE-2026-41273.12h
CVE-2026-676217.6 HIG
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.12h
CVE-2026-646644.3 MED
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.12h