PoC Archive PoC Archive

tag

Authorization-Bypass

Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)
CVE-2026-64640 cloud Patched
CVE-2026-64640cloudHIGH 8.1Patched2026-08-09gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)
CVE-2026-33186 (GHSA-p77j-4mvh-x3m3) network Patched
CVE-2026-33186networkHIGHPatched2026-07-05RustDesk Relay Session Downgrade and FileTransfer Authorization Scope Bypass
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkHIGHUnverified2026-07-03Nextcloud Federated Share OCM Bearer Token Scope Escalation to Sender WebDAV Access
None assigned as of 2026-07-03 cloud Unverified
None assigned as of 2026-07-03cloudHIGHUnverified2026-07-03MyBB 1.8.40 Limited Admin CP User-Manager to Full Administrator Privilege Escalation
None assigned as of 2026-07-03 (see Notes — CVE-2026-45115 identifies a separate, already-patched MyBB issue) web Unpatched
None assigned as of 2026-07-03webHIGHUnpatched2026-07-03Discourse Scoped API Key Pre-Route Authorization Bypass
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webHIGHUnverified2026-07-03Next.js i18n Middleware Bypass (CVE-2026-44573)
CVE-2026-44573 web Patched
CVE-2026-44573webHIGH 7.5Patched2026-05-17Next.js App Router Segment-Prefetch Middleware Bypass (CVE-2026-44575)
CVE-2026-44575 web Patched
CVE-2026-44575webHIGH 7.5Patched2026-05-17