CVE-2026-75044
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbit
CVSS
8.1
High
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Published: Aug 17, 2026 · Last modified: Aug 17, 2026 · CWE-862
0.2%EPSS · 30 days0.2%
2026-08-182026-08-24
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-782666.5 MED—
——0Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.1dCVE-2026-273646.5 MED—
——0Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.1dCVE-2026-715096.5 MED—
——0Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval status and approver identity fields. Attackers can manipulate workflow state fields through the REST API to advance expense reports to approved or closed status without possessing the dedicated approval right, while also creating forensic inconsistencies in audit records due to missing approval timestamps.1dCVE-2026-715086.5 MED—
——0Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite salary, bonus, hourly rate, daily rate, and weekly hours for any user without holding payroll rights, with the modified values appearing in payroll export reports.1dCVE-2026-715048.1 HIG—
——0Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder.1dCVE-2026-719339.1 CRI—
——0Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.1d