oss-security·1d ago highCVE-2026-82377: Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers#apache#apache-roller#cve-2026-82377CVE-2026-82377 17 sources
arXiv cs.CR·2d agoBeyond Centralized Policy Decision Points: Decentralized Sticky Policy Authorization through Evidence Quorums#sticky-policy#authorization#decentralizedResearch
CERT/CC Vulnerability Notes·3d ago highVU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers#kotaemon#cinnamon#idorCVE-2026-86867 3 min
Cyber Security News·3d agoOuterlimit Raises $16M to Build Zero Trust Security Layer for Autonomous AI Agents#outerlimit#ai-agents#zero-trust 2 sources 3 min
Full Disclosure·4d agoCVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2)#penpot#cve-2026-17613#authorizationCVE-2026-17613
arXiv cs.CR·5d agoZeroGate: Trust-Preserving Fast Paths for Governed AI Agent Runtimes#zerogate#ai-agents#authorizationAI safety & security1
oss-security·5d ago[OSSA-2026-040] OpenStack Blazar: Multiple authorization vulnerabilities in the Blazar V2 lease API (CVE-2026-93852, CVE-2026-93854)#openstack#blazar#authorizationCVE-2026-938522
oss-security·5d agoCVE-2026-75158: Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter#apache-airflow#cve-2026-75158#authorizationCVE-2026-75158 3 sources
arXiv cs.CR·5d agoActGov: Governing LLM Agent Actions via Policy-Constrained Validation#actgov#llm-agents#prompt-injectionAI safety & security1
oss-security·9d agoCVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)#access-control#apache-airflow#authorizationCVE-2026-75157
arXiv cs.CR·9d agoAuthorization Revocation for Long-Running AI Agents: Root-Scoped Quiescence under Delegation and Asynchronous Execution#ai-agents#authorization#revocationAI safety & security
arXiv cs.CR·9d agoLoopjacking: Hijacking Human-in-the-Loop Approval#loopjacking#human-in-the-loop#agentsAI safety & security
oss-security·11d agoCVE-2026-76186: Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity#apache-airflow#authorization#cookieCVE-2026-76186 2 sources
Cloudflare Blog·11d agoGive every teammate and agent the right level of access to your Workers#access-control#api-tokens#authorization 8 min
arXiv cs.CR·12d agoAuthorization Architectures for Tool-Using AI Agents#access-control#ai-agents#architectureAI safety & security
oss-security·12d agoCVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective#access-control#apache#authorizationCVE-2026-77181
oss-security·12d agoCVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioning#apache-syncope#authorization#cve-2026-75030CVE-2026-750301
oss-security·12d agoCVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles#apache#authorization#cve-2026-73470CVE-2026-73470
arXiv cs.CR·12d agoApproval Integrity and Recovery in LLM Answer Publication#authorization#evals#llm-securityAI safety & security
Help Net Security·13d agoPermify: Open-source authorization as a service#access-control#authorization#devtools1
arXiv cs.CR·16d agoIDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications#access-control#authorization#bolaResearch1
arXiv cs.CR·16d agoFrom Intent to Execution Grant: An Execution-Boundary Conformance Profile for High-Risk AI Actions#agent-security#ai-agents#authorizationAI safety & security1
Cyber Security News·16d agoHackers Can Turn AI Workflows Into Privileged Data-Stealing Proxies Without Jailbreaking Models#ai-security#authorization#data-exfiltration 3 min
CSO Online·16d agoAI workflows may be creating a dangerous new authorization blind spot#agent-security#ai-agents#authorization 5 min