CVE-2026-91713
Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.2
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L
- CWE
- CWE-862
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-8821 — Playbooks run owner channel membership permission bypass
- CVE-2026-20324 — Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability
- CVE-2026-75030 — Apache Syncope: Incomplete authorization checks for Group members deprovisioning
- CVE-2026-57139 — PraisonAI MCPServer exposes unauthenticated HTTP tools/call
- CVE-2026-57131 — praisonai: Jobs API exposes agent-execution endpoints with no authentication
- CVE-2026-41871 — Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
- CVE-2026-14349 — TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action
- CVE-2026-66887 — Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups