CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,985 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 164 of 180
- CVE-2026-40314MEDIUMCVSS 6.9EG 6.92026-06-02
NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/querie…
- CVE-2026-40349HIGHCVSS 8.8EG 8.82026-04-18
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` …
- CVE-2026-4038CRITICALCVSS 9.8EG 9.82026-03-20
The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including…
- CVE-2026-40474HIGHCVSS 7.6EG 7.62026-04-17
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of WgerPermissionMixin, so the permissi…
- CVE-2026-40480HIGHCVSS 7.1EG 7.12026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization checks. Although the legacy PersonView…
- CVE-2026-40502HIGHCVSS 8.8EG 8.82026-04-16
OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remo…
- CVE-2026-40543HIGHCVSS 8.8EG 8.82026-06-01
SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as we…
- CVE-2026-4056MEDIUMCVSS 5.4EG 5.42026-03-24
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the…
- CVE-2026-4057MEDIUMCVSS 4.3EG 4.32026-04-10
The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This…
- CVE-2026-40570MEDIUMCVSS 5.7EG 5.72026-04-21
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` returns complete customer profile data to any authenticated user without verifying mailbox…
- CVE-2026-40571MEDIUMCVSS 5.3EG 5.32026-06-02
NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This means that aut…
- CVE-2026-4058MEDIUMCVSS 4.3EG 4.32026-06-09
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_canc…
- CVE-2026-40581HIGHCVSS 8.1EG 8.12026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records and all associated data via a plain GET re…
- CVE-2026-40592MEDIUMCVSS 5.9EG 5.92026-04-21
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verif…
- CVE-2026-40601HIGHCVSS 7.5EG 7.52026-04-30
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes POST /api/chart/:chart_id/query without authentication. The endpoint only ch…
- CVE-2026-40623HIGHCVSS 8.1EG 8.12026-04-24
A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on s…
- CVE-2026-4063MEDIUMCVSS 4.3EG 4.32026-03-13
The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8…
- CVE-2026-4064HIGHCVSS 8.3EG 8.32026-03-17
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including …
- CVE-2026-4065MEDIUMCVSS 5.4EG 5.42026-04-07
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The…
- CVE-2026-4066MEDIUMCVSS 4.3EG 4.32026-03-23
The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for a…
- CVE-2026-40722MEDIUMCVSS 5.5EG 5.52026-06-17
Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.
- CVE-2026-40723MEDIUMCVSS 4.3EG 4.32026-06-17
Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.
- CVE-2026-40726HIGHCVSS 8.2EG 8.22026-06-17
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
- CVE-2026-40728MEDIUMCVSS 4.3EG 4.32026-04-15
Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Blocks: from n/a through <= 1.8.3.
- CVE-2026-40729MEDIUMCVSS 4.3EG 4.32026-04-15
Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5.
- CVE-2026-40730MEDIUMCVSS 5.3EG 5.32026-04-15
Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.…
- CVE-2026-40740MEDIUMCVSS 5.4EG 5.42026-04-15
Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.7.
- CVE-2026-40741HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.
- CVE-2026-40742MEDIUMCVSS 5.3EG 5.32026-04-15
Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio AB Testing: from n/a through <= 8.2.8.
- CVE-2026-40743MEDIUMCVSS 6.5EG 6.52026-06-15
Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.
- CVE-2026-40763MEDIUMCVSS 5.3EG 5.32026-04-15
Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056.
- CVE-2026-40773MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.
- CVE-2026-40774HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.
- CVE-2026-40775HIGHCVSS 7.3EG 7.32026-06-15
Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
- CVE-2026-40776HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
- CVE-2026-40778MEDIUMCVSS 5.3EG 5.32026-04-15
Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.2.
- CVE-2026-40782MEDIUMCVSS 6.5EG 6.52026-06-15
Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.
- CVE-2026-40786MEDIUMCVSS 4.3EG 4.32026-04-15
Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3.
- CVE-2026-40788HIGHCVSS 7.1EG 7.12026-06-15
Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.
- CVE-2026-40793MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.
- CVE-2026-40794MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in myCred <= 3.0.3 versions.
- CVE-2026-40795MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in Amelia <= 2.2 versions.
- CVE-2026-40809MEDIUMCVSS 6.5EG 6.52026-06-16
Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.
- CVE-2026-40870HIGHCVSS 7.5EG 7.52026-04-21
Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the root level `commentable` field in the API allows access to all commentable resources within the platform, without any pe…
- CVE-2026-40937HIGHCVSS 8.3EG 8.32026-04-22
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src/admin/handlers/event.rs` use a `check_permissions` helper that validates authentication o…
- CVE-2026-4094HIGHCVSS 8.1EG 8.12026-05-15
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes …
- CVE-2026-40976CRITICALCVSS 9.1EG 9.12026-04-28
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configurat…
- CVE-2026-4100HIGHCVSS 7.1EG 7.12026-05-02
The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_p…
- CVE-2026-41014MEDIUMCVSS 4.3EG 4.32026-06-01
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configur…
- CVE-2026-4109MEDIUMCVSS 4.3EG 4.32026-04-14
The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all ver…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →