CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,983 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 154 of 180
- CVE-2026-27393MEDIUMCVSS 5.3EG 5.32026-05-21
Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 WOW Styler: from n/a through 1.7.6.
- CVE-2026-27396HIGHCVSS 7.3EG 7.32026-03-05
Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6.
- CVE-2026-27398MEDIUMCVSS 5.3EG 5.32026-05-25
Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16.
- CVE-2026-27399MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
- CVE-2026-27405MEDIUMCVSS 6.5EG 6.52026-05-20
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
- CVE-2026-27409MEDIUMCVSS 5.3EG 5.32026-07-01
Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly... Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels…
- CVE-2026-27416MEDIUMCVSS 5.3EG 5.32026-05-07
Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF Poster: from n/a through 2.4.1.
- CVE-2026-27418MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
- CVE-2026-27422MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
- CVE-2026-27423MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
- CVE-2026-27424MEDIUMCVSS 4.3EG 4.32026-05-20
Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11.
- CVE-2026-27433MEDIUMCVSS 6.5EG 6.52026-07-02
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
- CVE-2026-27435MEDIUMCVSS 5.3EG 5.32026-07-01
Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.
- CVE-2026-27454MEDIUMCVSS 5.3EG 5.32026-03-19
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The display_post method called post.revert_…
- CVE-2026-27457MEDIUMCVSS 4.3EG 4.32026-02-26
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permiss…
- CVE-2026-27468HIGHCVSS 8.2EG 8.22026-02-24
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe …
- CVE-2026-27471CRITICALCVSS 9.1EG 9.12026-02-21
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been f…
- CVE-2026-27484MEDIUMCVSS 4.3EG 4.32026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, instead of trusted runtime sender context.…
- CVE-2026-27491MEDIUMCVSS 4.3EG 4.32026-03-19
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a sta…
- CVE-2026-27604CRITICALCVSS 10.0EG 10.02026-06-23
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` end…
- CVE-2026-27608HIGHCVSS 8.1EG 8.12026-02-25
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to…
- CVE-2026-27638HIGHCVSS 7.1EG 7.12026-02-26
Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being operated on. Any authenti…
- CVE-2026-27672MEDIUMCVSS 4.3EG 4.32026-04-14
The Material Master application does not enforce authorization checks for authenticated users when executing reports, resulting in the disclosure of sensitive information. This vulnerability has a low impact on confidentiality and does not…
- CVE-2026-27673MEDIUMCVSS 4.9EG 4.92026-04-14
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Conf…
- CVE-2026-27676MEDIUMCVSS 4.3EG 4.32026-04-14
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability resul…
- CVE-2026-27677MEDIUMCVSS 6.5EG 6.52026-04-14
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could update and delete child entities via OData services without proper authorization. This vulnerability has a high impact on …
- CVE-2026-27678MEDIUMCVSS 6.5EG 6.52026-04-14
Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has …
- CVE-2026-27679MEDIUMCVSS 6.5EG 6.52026-04-14
Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has…
- CVE-2026-27686MEDIUMCVSS 5.9EG 5.92026-03-10
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration…
- CVE-2026-27687MEDIUMCVSS 5.8EG 5.82026-03-10
Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does…
- CVE-2026-27688MEDIUMCVSS 5.0EG 5.02026-03-10
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary pr…
- CVE-2026-27708HIGHCVSS 7.1EG 7.12026-06-24
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authent…
- CVE-2026-27769LOWCVSS 2.7EG 2.72026-04-15
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed…
- CVE-2026-27771HIGHCVSS 8.2EG 8.42026-07-03
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
- CVE-2026-27783MEDIUMCVSS 4.3EG 4.32026-06-16
Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
- CVE-2026-27792MEDIUMCVSS 5.4EG 5.42026-02-27
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified in the application starting in version 2.7.0 and prior to version 3.1.0. It allows authenti…
- CVE-2026-27796HIGHCVSS 7.5EG 7.52026-03-07
Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata …
- CVE-2026-27833HIGHCVSS 7.5EG 7.52026-04-03
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing hi…
- CVE-2026-27836HIGHCVSS 7.5EG 7.52026-02-27
phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active user accounts without any authentication, CSRF protection, captcha, or configuration checks…
- CVE-2026-27946MEDIUMCVSS 6.5EG 6.52026-02-26
ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual ver…
- CVE-2026-27954MEDIUMCVSS 6.5EG 6.52026-02-26
Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without cal…
- CVE-2026-28038MEDIUMCVSS 6.5EG 6.52026-03-05
Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Pa…
- CVE-2026-28070MEDIUMCVSS 5.3EG 5.32026-03-19
Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP eMember: from n/a through v10.2.2.
- CVE-2026-28071MEDIUMCVSS 6.3EG 6.32026-03-05
Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pixfort Core: from n/a through <= 3.2.22.
- CVE-2026-28076HIGHCVSS 7.5EG 7.52026-03-05
Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Guff: from n/a through <= 1.0.1.
- CVE-2026-28080MEDIUMCVSS 4.3EG 4.32026-03-06
Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO PRO: from n/a through 3.0.95.
- CVE-2026-28104MEDIUMCVSS 6.5EG 6.52026-03-05
Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Site Suggest: from n/a through <= 1.3.9.
- CVE-2026-2819MEDIUMCVSS 6.3EG 6.32026-02-20
A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to mi…
- CVE-2026-28193HIGHCVSS 5.3EG 8.82026-02-25
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
- CVE-2026-28195MEDIUMCVSS 4.3EG 4.32026-02-25
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →