Known Vulnerabilities for Access Management by Forgerock
Listed below are 9 of the newest known vulnerabilities associated with "Access Management" by "Forgerock".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-88959 json | Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authent... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88864 json | Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST.... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88770 json | A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue oc... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-88006 json | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's O... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-86774 json | Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cas... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-86762 json | Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-86543 json | knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no p... | Not Provided | 2026-09-07 | 2026-09-07 |
| CVE-2026-86464 json | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Mana... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-86347 json | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for ... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86193 json | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-sup... | Not Provided | 2026-09-05 | 2026-09-08 |