Skip to content
Threat Feed

Tag

Api-Security

36 briefs RSS
high threat

Unauthenticated Administrative Access in Semantic MediaWiki smwtask API

The Semantic MediaWiki smwtask API module fails to enforce authorization, enabling unauthenticated remote attackers to perform sensitive information disclosure, queue administrative maintenance jobs, and manipulate stored semantic data.

exploited Semantic MediaWiki +1 api-security broken-access-control webserver web-security xss cms
1r 1t
high advisory

Cross-Tenant IDOR in Convoy API Exposes Broker Credentials

Convoy versions up to and including 26.6.2 contain an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to leak plaintext message broker credentials from other tenants.

convoy idor credential-leak api-security
2t 1c
high advisory

Umbraco Delivery API Authorization Bypass via Node Expansion

Umbraco CMS contains an authorization bypass vulnerability (CVE-2026-69197) in the Delivery API where protected content is leaked when referenced by an unprotected node through expansion parameters.

Umbraco CMS authorization-bypass api-security umbraco cve-2026-69197
1t 1c
high advisory

Authorization Bypass in SigNoz Trace-Funnel Analytics

SigNoz versions 0.88.0 through 0.141.0 contain an authorization bypass vulnerability allowing unauthenticated remote attackers to query sensitive trace analytics via the trace-funnel endpoint.

SigNoz +2 authorization-bypass api-security observability sql-injection vulnerability web-application webserver injection
2r 1t 1c updated
high advisory

Authorization Bypass in Flowise openai-realtime Endpoints

Flowise versions prior to 3.1.4 contain an authorization flaw in the openai-realtime endpoint, enabling authenticated users to access and execute tools in unauthorized workspaces via cross-workspace ID manipulation.

Flowise vulnerability auth-bypass api-security
1c
high advisory

Remote Command Injection in 0x4m4 HexStrike AI

A command injection vulnerability in HexStrike AI allows remote unauthenticated attackers to execute arbitrary OS commands via the Execute Endpoint.

HexStrike AI +1 remote-code-execution vulnerability command-injection api-security
1r 3t 1c
high advisory

Insecure Direct Object Reference in CAPEv2 REST API

CAPEv2 versions up to commit 471ee4b contain an IDOR vulnerability allowing authenticated users to access and delete arbitrary analysis tasks.

CAPEv2 webserver idor api-security
1t 1c
high advisory

Authentication Bypass in WARP-Clash-API via SECRET_KEY Manipulation

A publicly disclosed vulnerability in the WARP-Clash-API authorized function allows remote unauthenticated access by manipulating the SECRET_KEY argument.

WARP-Clash-API authentication-bypass api-security unmaintained-software
1t 1c
high advisory

CVE-2026-88864 - Authorization Bypass in Capgo SSO Provisioning

An authorization vulnerability in the public.sso_providers table of Capgo allows attackers with an ordinary API key to bypass domain verification and enforce arbitrary SSO settings, leading to authentication disruption.

capgo.app sso-bypass cloud-security api-security
1t 1c
medium advisory

Information Disclosure Vulnerability in Bruno

A vulnerability in the Bruno API client allows a remote, unauthenticated attacker to disclose sensitive information, potentially leading to unauthorized data exposure.

Bruno information-disclosure api-security
1t
high advisory

Authorization Bypass in Helicone VaultManager via Provider Key Retrieval

An authorization bypass vulnerability in Helicone's VaultManager allows authenticated users to exfiltrate plaintext provider API keys from other organizations due to missing access control checks.

VaultManager authorization-bypass credential-access api-security
1t 1c
high advisory

Information Disclosure in ReadToMyShoe via Google Cloud API Key Leakage

ReadToMyShoe version 0.2.0 is vulnerable to information disclosure (CVE-2023-27587) where sensitive Google Cloud API keys are exposed within error messages during failed Text-to-Speech (TTS) requests.

Readtomyshoe +1 information-disclosure cloud-security api-security
1t 1c
high threat

Missing Authorization in Kirby CMS REST API Chunked Upload Handler

Authenticated users without file upload permissions can exploit a missing authorization check in Kirby CMS to exhaust server storage via incomplete chunked file uploads, leading to denial-of-service.

exploited Kirby CMS +1 web-application denial-of-service api-security web-application-vulnerability path-traversal cms
1r 1t 1c
high advisory

Server-Side Request Forgery in Portkey AI Gateway

Portkey AI Gateway through 1.15.2 is vulnerable to SSRF via the /v1/proxy/* route, allowing unauthenticated attackers to query internal services and exfiltrate API keys.

AI Gateway ssrf api-security cloud
1r 1t 1c
high advisory

Gophish API Authentication Middleware Bypass

Gophish versions through 0.12.1 contain a vulnerability in the API authentication middleware that fails to enforce account lockout and password change requirements, allowing attackers with valid API keys to maintain persistent unauthorized access.

Gophish web-application authentication-bypass api-security
1t 1c
critical advisory

CVE-2026-82266: Unauthenticated Redpanda Admin API Access

Redpanda versions 26.2.2 and earlier insecurely expose the Admin API on port 9644 by default without authentication enabled, allowing remote attackers to perform superuser actions.

Redpanda vulnerability remote-code-execution api-security
1r 1t 1c
high advisory

9router Authentication Bypass and SSRF via Host Header Spoofing

An authentication bypass in 9router 0.4.80 and earlier allows remote attackers to spoof the 'Host' header, gaining unauthorized access to API proxy endpoints, enabling quota theft via AI relay and server-side request forgery (SSRF).

9router +1 authentication-bypass ssrf api-security web-vulnerability authorization-bypass llm-proxy
2r 2t 1c
high advisory

Arbitrary File Write Vulnerability in PraisonAI Agents

The FileMemory component in praisonaiagents versions 1.6.52 and earlier fails to sanitize user-supplied identifiers, enabling path traversal attacks that result in arbitrary JSON file creation or overwriting.

praisonaiagents vulnerability path-traversal python ssrf cloud-security authentication-bypass insecure-design api-security
5t 1c
high advisory

IDOR Vulnerability in Label Studio Annotation API

Label Studio contains an insecure direct object reference (IDOR) vulnerability, CVE-2026-76073, allowing authenticated users to read, modify, or delete annotations across organizational boundaries by enumerating sequential identifiers.

Label Studio idor api-security data-exfiltration
2t 1c
high advisory

Insufficient Access Control in docker-socket-proxy

An access control vulnerability in docker-socket-proxy (CVE-2026-78122) allows unauthenticated adjacent attackers to bypass restrictions and exfiltrate container filesystems via unauthorized API requests.

PoC docker-socket-proxy vulnerability container-security api-security
1r 1t 1c
critical advisory

Authentication Bypass in SiYuan Publish API

SiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to retrieve decrypted content from encrypted notebooks.

SiYuan +3 access-control web-vulnerability authentication-bypass information-disclosure api-security remote-code-execution vulnerability pdf-processing +9
7r 19t 5c updated
high advisory

Authentication Bypass Vulnerability in CentreStack

CentreStack versions prior to 17.2 are vulnerable to an authentication bypass that allows unauthenticated attackers to manipulate account settings and enumerate system data via exposed API endpoints.

CentreStack authentication-bypass cve-2026-54367 api-security
1t 1c
low advisory

Zitadel User API Verification Code Disclosure Vulnerability

An improper permission check in Zitadel's user API allows authenticated users to retrieve verification codes for arbitrary contact information, facilitating unauthorized verification of email addresses and phone numbers.

Zitadel 4.x +2 identity-management auth-bypass api-security
1t 1c
critical advisory

Unauthenticated API Access in AMMOS Instrument Toolkit DSN Interface

The AMMOS Instrument Toolkit (AIT) DSN Interface prior to version 2.2.2 contains a missing authentication vulnerability in the Space Link Extension interface manager, allowing unauthenticated attackers to invoke sensitive API routes.

AMMOS Instrument Toolkit api-security authentication-bypass cve-2026-60113
1t 1c
high advisory

Swagger-typescript-api Vulnerable to Authorization Token Exfiltration via Spec $ref

The `swagger-typescript-api` tool is vulnerable to authorization token exfiltration. When a developer provides an `--authorizationToken` to fetch an OpenAPI specification, the tool attaches this token to all subsequent HTTP requests made while resolving external `$ref` URLs within the spec. Critically, it lacks same-origin checks, allowing a malicious OpenAPI spec containing a `$ref` to an attacker-controlled URL to cause the authorization token (e.g., GitHub PAT, OAuth bearer) to be sent verbatim to the attacker. This credential disclosure provides an attacker with the same scope of access as the stolen token, affecting development environments, CI/CD pipelines, and multi-tenant SaaS platforms.

swagger-typescript-api credential-theft supply-chain software-development openapi api-security nodejs code-injection npm +2
1r 5t
high advisory

SuperPlane Broken Object-Level Authorization Vulnerability (CVE-2026-57510)

A critical broken object-level authorization vulnerability in SuperPlane's CanvasService gRPC handlers, tracked as CVE-2026-57510, allows authenticated users with viewer-level access to bypass organization scoping and access resources across tenant boundaries, leading to data collection and system impact.

SuperPlane < 0.27.0 authorization-bypass api-security saas cloud multi-tenancy grpc cve
3t 1c
high advisory

Improper Privilege Escalation in Anchore Enterprise User Management API

An improper privilege escalation vulnerability (CVE-2026-63727) exists in Anchore Enterprise versions 5.11.0 to 5.27.1 and 6.0.0, specifically within the user management API, allowing an authenticated attacker to issue a crafted API call to modify user permissions and gain elevated access to resources and operations, such as granting write access to a read-only user, with fixes available in versions 5.27.2 and 6.0.1.

Anchore Enterprise +1 privilege-escalation api-security vulnerability anchore
1t 1c
high advisory

LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback

An authentication bypass vulnerability (CVE-2026-59822) exists in LiteLLM's MCP Streamable HTTP endpoint, affecting versions prior to 1.84.0, allowing an unauthenticated attacker to exploit a fallback path that replaces failed key validation with an empty authentication object, leading to the establishment of an authenticated MCP session using arbitrary Bearer tokens, enabling access to configured MCP tools and connected services.

LiteLLM +1 authentication-bypass api-security web-vulnerability
1t 1c updated
critical advisory

IBM Langflow OSS Improper Authentication Vulnerability

A remote attacker can gain full administrative access to IBM Langflow OSS versions 1.0.0 through 1.10.0 by exploiting an improper authentication vulnerability. The /api/v1/login/auto_login endpoint, when the default AUTO_LOGIN configuration is enabled, issues long-lived superuser bearer tokens without requiring authentication. This allows an unauthenticated network attacker to obtain these tokens and achieve superuser privileges. Additionally, permissive Cross-Origin Resource Sharing (CORS) settings could expose these tokens to unintended origins, exacerbating the risk.

Langflow OSS vulnerability web-application api-exploitation improper-authentication cve privilege-escalation code-injection critical-vulnerability +4
2r 5t 3c
high threat

B2B Platform Paywall Bypass via Client-Side Boolean Manipulation

An autonomous Red Agent discovered a critical business-logic flaw in a B2B platform's data API, allowing free-tier users to bypass the paywall and access premium, unmasked contact data for over 600 million profiles by adding a boolean flag, `unmaskContactData: true`, to standard API requests, due to the backend accepting client-controlled parameters without verifying user entitlements.

Red Agent business-logic-flaw authorization-bypass api-security red-team data-collection
2t
high advisory

Unauthenticated API Key Use in NetLicensing-MCP HTTP Mode

An unauthenticated vulnerability exists in netlicensing-mcp (version 0.1.5 and earlier) when operating in HTTP transport mode, where the ApiKeyMiddleware fails to enforce authentication for requests lacking a client API key, causing the application to fall back to the server's NETLICENSING_API_KEY environment variable for upstream calls, allowing an unauthenticated network attacker to invoke any MCP tool under the server operator's identity and account quota.

netlicensing-mcp web-vulnerability missing-authentication api-security supply-chain http
5t
high advisory

Capgo API Key Information Disclosure Vulnerability (CVE-2026-56303)

An information disclosure vulnerability (CVE-2026-56303) in Capgo versions before 12.128.2 allows unauthenticated attackers to retrieve sensitive API key metadata, including user ID, mode, organization scoping, and expiration details, by exploiting a misconfigured PostgreSQL function via the `/rest/v1/rpc/find_apikey_by_value` endpoint.

Capgo information-disclosure vulnerability api-security web-application
1r 1t 1c
critical advisory

Critical Unauthenticated API Access in Esri Portal for ArcGIS (CVE-2026-13019)

A critical missing authentication vulnerability (CVE-2026-13019) in Esri Portal for ArcGIS versions 12.1 and earlier allows a remote, unauthenticated attacker to access unprotected critical APIs, impacting deployments on Windows, Linux, and Kubernetes environments.

Portal for ArcGIS 12.1 and earlier vulnerability esri arcgis unauthenticated-access api-security rce
1t 1c
critical advisory

Critical Unauthenticated API Vulnerabilities in 9Router Leading to Data Leak and RCE Risk

Multiple critical unauthenticated API vulnerabilities in 9Router versions up to 0.4.41 allow an attacker to perform full CRUD operations on provider connections, leak plaintext API keys, and access sensitive conversation history, posing risks of data exfiltration and denial of service.

9Router <= 0.4.41 web-vulnerability api-security data-exfiltration credential-access denial-of-service unauthenticated-access
3r 5t
medium advisory

Pipecat Telephony Runner Unauthenticated Call-Control Abuse

An unauthenticated remote attacker can leverage a missing authorization vulnerability (CWE-862) in the Pipecat development runner's `/ws` WebSocket endpoint to supply a crafted `callSid` in a handshake message, compelling the server to use its configured Twilio, Telnyx, or Plivo credentials to issue authenticated API requests that terminate active calls, resulting in denial of service and credential abuse.

pipecat development runner api-security websocket telephony cwe-862 python
1r 3t 3i
high advisory

Flowise Public Chatflow Endpoint Exposes Sensitive Data

Flowise versions 3.0.13 and earlier expose sensitive information, including credential IDs, plaintext API keys, and passwords, through the `GET /api/v1/public-chatflows/:id` endpoint, leading to account compromise and revealing internal architecture details.

Flowise credential-leak api-security
2r 2t