Tag
critical
advisory
Esri Portal for ArcGIS Incorrect Authorization Vulnerability (CVE-2026-33519)
2 rules 1 TTP 1 CVECVE-2026-33519 is a critical vulnerability in Esri Portal for ArcGIS 11.4, 11.5, and 12.0, where incorrect authorization checks on developer credentials can lead to unauthorized privilege escalation on Windows, Linux, and Kubernetes deployments.
esri
arcgis
privilege-escalation
incorrect-authorization
cve-2026-33519
webserver
2r
1t
1c
high
advisory
XenForo OAuth2 Unauthorized Scope Request Vulnerability
2 rules 1 TTP 1 CVE 2 IOCsXenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes, potentially allowing client applications to gain access beyond their intended authorization level due to improper authorization checks.
cve-2025-71278
oauth2
xenforo
incorrect-authorization
2r
1t
1c
2i
high
advisory
Vitals ESP Incorrect Authorization Vulnerability (CVE-2026-4639)
2 rules 1 TTPCVE-2026-4639 is an Incorrect Authorization vulnerability in Galaxy Software Services' Vitals ESP, allowing authenticated remote attackers to perform administrative functions and escalate privileges.
incorrect-authorization
privilege-escalation
web-application
2r
1t