CVE-2026-66701
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
CVSS
5.3
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 6 ago 2026 · Última mod.: 6 ago 2026 · CWE-862
Sin historial EPSS suficiente todavía.
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-54201——
——0Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks
when serving these log files. As a result, attackers can obtain
sensitive error information or internal application details, potentially
aiding in further attacks. This issue affects TeamDavid through Rollout 524.6hCVE-2026-143659.8 CRÍ—
——0The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts.11hCVE-2026-119076.5 MED—
——0The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access all Stream activity records via the Heartbeat API.11hCVE-2026-6566710.0 CRÍ—
——0Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.14hCVE-2026-628309.9 CRÍ—
——0Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.16hCVE-2026-706367.5 ALT—
——0Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to bypass all authentication and authorization checks, triggering unauthorized OAuth token rotation against credentials belonging to any workspace and potentially disrupting dependent OAuth integrations. This is a bypass of CVE-2026-41273.18h