CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,986 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 169 of 180
- CVE-2026-47089MEDIUMCVSS 4.3EG 4.32026-07-16
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had w…
- CVE-2026-47100HIGHCVSS 7.5EG 7.52026-05-19
Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugi…
- CVE-2026-47120HIGHCVSS 7.1EG 7.12026-05-23
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check). …
- CVE-2026-47125HIGHCVSS 8.8EG 8.82026-05-23
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitutio…
- CVE-2026-47129HIGHCVSS 8.1EG 8.12026-07-20
NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions of NextCRM. The application…
- CVE-2026-47163HIGHCVSS 7.2EG 7.22026-06-11
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any guild member who can invoke slash commands can use /automod add, /automod remove, and /automod list because the command …
- CVE-2026-47193HIGHCVSS 7.5EG 7.52026-06-26
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in…
- CVE-2026-47197HIGHCVSS 7.2EG 7.22026-06-12
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can use the bot to moderate users above them in the Discord role hierarchy, as long as the bot itself outranks the target.…
- CVE-2026-47281CRITICALCVSS 9.6EG 9.62026-06-09
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-47343HIGHCVSS 7.2EG 7.22026-06-09
Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This issue affects TYPO3 C…
- CVE-2026-47346HIGHCVSS 7.6EG 7.62026-06-09
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to e…
- CVE-2026-47349MEDIUMCVSS 5.3EG 5.32026-06-09
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.…
- CVE-2026-47350MEDIUMCVSS 5.3EG 5.32026-06-09
Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.
- CVE-2026-47351MEDIUMCVSS 5.3EG 5.32026-06-09
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue af…
- CVE-2026-47352MEDIUMCVSS 5.3EG 5.32026-06-09
Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS version…
- CVE-2026-47394HIGHCVSS 8.7EG 8.72026-05-29
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named four vulnerable handlers in `mcp_server/adapters/cli_tools.py`. Commi…
- CVE-2026-47405HIGHCVSS 8.8EG 8.82026-05-29
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own rol…
- CVE-2026-47409HIGHCVSS 8.1EG 8.12026-05-29
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated o…
- CVE-2026-47411MEDIUMCVSS 6.5EG 6.52026-06-01
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is …
- CVE-2026-47412HIGHCVSS 8.1EG 8.12026-06-01
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `requi…
- CVE-2026-47413CRITICALCVSS 9.6EG 9.62026-06-01
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only b…
- CVE-2026-47416CRITICALCVSS 9.6EG 9.62026-05-29
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `re…
- CVE-2026-47422MEDIUMCVSS 5.3EG 5.32026-07-10
Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.
- CVE-2026-4764CRITICALCVSS 9.4EG 9.42026-06-11
A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a ma…
- CVE-2026-47657HIGHCVSS 7.1EG 7.12026-07-21
HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Sp…
- CVE-2026-47688HIGHCVSS 8.2EG 8.22026-07-21
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via…
- CVE-2026-47721MEDIUMCVSS 6.3EG 6.32026-06-08
FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions ## Summary An authorization issue in the Scheduler API allowed authenticated non-admin users to create or modify scheduled actions…
- CVE-2026-47724CRITICALCVSS 9.9EG 9.92026-06-08
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits t…
- CVE-2026-47728MEDIUMCVSS 4.3EG 4.32026-05-26
Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An authenticated user with access to one pro…
- CVE-2026-47740HIGHCVSS 8.1EG 8.12026-05-29
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orde…
- CVE-2026-47742MEDIUMCVSS 6.5EG 6.52026-05-29
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regar…
- CVE-2026-47745MEDIUMCVSS 6.5EG 6.52026-05-29
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete) that were rendered for any authenticat…
- CVE-2026-47755MEDIUMCVSS 6.5EG 6.52026-07-23
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another c…
- CVE-2026-4795MEDIUMCVSS 6.5EG 6.52026-05-26
A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versio…
- CVE-2026-48008MEDIUMCVSS 6.5EG 6.52026-06-04
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /ap…
- CVE-2026-48014MEDIUMCVSS 6.5EG 6.52026-06-04
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in src/Core/Checkout/Order/A…
- CVE-2026-4807MEDIUMCVSS 6.5EG 6.52026-05-07
The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the pu…
- CVE-2026-48119HIGHCVSS 7.1EG 7.12026-06-01
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results for other users' services. This issue has …
- CVE-2026-4812MEDIUMCVSS 5.3EG 5.32026-04-15
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter …
- CVE-2026-48127MEDIUMCVSS 5.3EG 5.32026-07-10
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.2…
- CVE-2026-48151HIGHCVSS 7.5EG 7.52026-05-27
Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema…
- CVE-2026-4818HIGHCVSS 8.1EG 8.12026-03-31
In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
- CVE-2026-4843MEDIUMCVSS 4.3EG 4.32026-05-21
The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possible…
- CVE-2026-48492MEDIUMCVSS 6.5EG 6.52026-06-23
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a …
- CVE-2026-48500MEDIUMCVSS 6.5EG 6.52026-06-22
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the…
- CVE-2026-48582CRITICALCVSS 9.6EG 9.62026-06-19
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
- CVE-2026-48592MEDIUMCVSS 5.3EG 5.32026-05-26
Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthorized job worker substitution. The handle_event("save-job", ...) handler in 'Elixir.Oban.Web.Jobs.DetailComponent' does…
- CVE-2026-48709LOWCVSS 3.7EG 3.72026-06-15
OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.go does not perform any authentication or authorization checks. Unli…
- CVE-2026-48783MEDIUMCVSS 4.8EG 4.82026-06-17
Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's clai…
- CVE-2026-48797CRITICALCVSS 9.3EG 9.32026-06-17
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training …
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →