Tag: authorization bypass
5 articles

Dell Urges Admins to Patch CSM Flaws Exploiting Authorization Controls
Dell is urging admins to patch two critical CSM flaws, CVE-2026-63688 and CVE-2026-63692, that allow unauthenticated attackers to gain complete control over storage resources, potentially leading to unauthorized access and manipulation. These maximum-severity vulnerabilities can be exploited to bypass authorization controls and access sensitive storage backend administrator credentials.

AI Workflows Expose New Backdoor Vulnerability
Imagine a hidden vulnerability in AI workflows that lets malicious actors sneak in and access production systems without needing human credentials - a threat that's easy to overlook but hard to ignore. Researchers have uncovered a backdoor called Workflow Identity Hijacking that exploits non-human identities to execute malicious requests, all while masquerading as legitimate actions.

FIFA Exposes Vulnerability in Application Backends
A shocking vulnerability was discovered in the backends of two FIFA applications, Football Data Platform and Commentator Information System, where authorization checks were surprisingly handled by client-side code, leaving them open to potential exploitation. This flaw highlights a critical error in application design, where security checks were outsourced to the user interface, rather than being rigorously enforced on the server-side.

LiteLLM Vulnerability Chain Enables Low-Privilege Server Takeover
A shocking vulnerability chain in LiteLLM has been discovered, allowing hackers to hijack servers with just a low-privilege account, and experts warn it's a critical threat with a near-perfect CVSS score of 9.9. By chaining three distinct bugs, attackers can escalate their access to full admin rights and run code on the server.

AWS Discloses Flaw in Quick Access Control
AWS swiftly addressed a security flaw in Quick Access, discovered by Fog Security, which could have allowed unauthorized users to bypass access controls, and fortunately, no customer data was compromised. The issue was resolved in March 2026, with no action required from customers.