All CosmicBytez Labs articles tagged #Access Control, across news, security advisories, how-to guides, and projects.
CVE-2026-16259 (CVSS 9.8) lets attackers hijack any account on sites running Uix UserCenter — no login needed, and no fix exists yet.
Scriban's TypedObjectAccessor fails to enforce setter visibility, letting template code write private and init-only .NET properties (CVSS 9.8 Critical).
Grav API plugin before 1.0.13 lets low-privilege API keys enable Twig processing on pages via a broken scope gate in PagesController.
The HT Contact Form plugin before 2.9.3 allows any unauthenticated user to read saved form drafts containing visitor names, emails, and physical addresses via a completely unprotected API endpoint.
Incorrect access control in the Executive Services component of NASA cFS v7.0.1 allows attackers to execute arbitrary code by placing a malicious shared object on target storage. CVSS score 9.1.
A critical broken access control flaw (CVSS 9.8) in IBM WebSphere Application Server 8.5 and 9.0 allows attackers to escalate privileges via the administrative console.
A critical access control vulnerability in OpENer 2.3.0 allows unauthenticated attackers to send privileged encapsulation commands using arbitrary session...
A high-severity improper privilege management flaw in SourceCodester's Online Examination and Learning Management System 1.0 allows remote attackers to...
The original shadow AI concern — employees pasting sensitive data into public tools — has been overtaken by a more dangerous problem: unsanctioned AI apps...
A security researcher discovered that FIFA's unenforced Microsoft Entra access controls could have allowed an attacker to hijack live World Cup broadcast...
HaPe PKH 1.1, a PHP-based web application, fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to...
A critical CVSS 9.1 access control flaw in the WP Travel Pro WordPress plugin allows unauthenticated attackers to delete any user account — including...
A CVSS 10.0 improper access control flaw in UniFi OS allows any network-accessible attacker to make unauthorized changes to the underlying system with no...
A critical improper access control flaw in Azure Managed Instance for Apache Cassandra allows an authorized network attacker to execute arbitrary code,...
A critical privilege escalation vulnerability in Microsoft Partner Center allows an authorized attacker to elevate their privileges over a network,...
A critical improper access control vulnerability in EspoCRM's built-in formula scripting engine allows authenticated administrators to overwrite the...
A critical insecure direct object reference vulnerability allows authenticated users to pivot to any other user's profile by modifying an id parameter in...