CVE-2026-81294
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 2, 2026 · Last modified: Sep 2, 2026 · CWE-266
Not enough EPSS history yet.
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-848075.4 MED—
——0Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or activity whose name matches an existing team; because the endpoints POST /api/customers/{id}/team, POST /api/projects/{id}/team, and POST /api/activities/{id}/team reuse an existing team of the same name and add the current user as teamlead without verifying that the user is authorized to manage that team, the attacker gains unauthorized team-lead (administration) rights over the existing team. Fixed in 2.65.0.1dCVE-2026-817698.8 HIG—
——0Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.
This issue affects Booking Hub: from n/a through 1.3.1.1dCVE-2026-841158.3 HIG20.5%
——6A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 is sufficient to fix this issue. It is recommended to upgrade the affected component.2dCVE-2026-812977.5 HIG22.3%
——7Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.2dCVE-2026-828355.4 MED13.1%
——4A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id can lead to improper access controls. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.2dCVE-2026-828345.4 MED12.5%
——4A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. This affects the function LabelList of the file /v1/projects/1/category-types of the component Bulk-Delete Endpoint. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.1d