CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,986 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 170 of 180
- CVE-2026-4881MEDIUMCVSS 6.5EG 6.52026-06-04
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.
- CVE-2026-48811MEDIUMCVSS 4.3EG 4.32026-05-29
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete an internal note (private thread) from any conversation, even after that user's ac…
- CVE-2026-48835HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
- CVE-2026-48873HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.
- CVE-2026-4888MEDIUMCVSS 4.3EG 4.32026-05-27
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to…
- CVE-2026-48881CRITICALCVSS 9.1EG 9.12026-06-15
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
- CVE-2026-48883HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
- CVE-2026-48887MEDIUMCVSS 6.5EG 6.52026-06-15
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
- CVE-2026-48941MEDIUMCVSS 6.5EG 6.52026-06-25
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/`
- CVE-2026-48969MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
- CVE-2026-48971MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for WooCommerce: from n/a through 2.5…
- CVE-2026-48973MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14.
- CVE-2026-49045MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11.
- CVE-2026-49047MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27.
- CVE-2026-49051MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6.
- CVE-2026-49052MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
- CVE-2026-49053MEDIUMCVSS 5.3EG 5.32026-05-27
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
- CVE-2026-49054MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly... Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Leve…
- CVE-2026-49057HIGHCVSS 7.5EG 7.52026-06-17
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
- CVE-2026-49065HIGHCVSS 8.2EG 8.22026-06-15
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
- CVE-2026-49070HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
- CVE-2026-49072MEDIUMCVSS 6.5EG 6.52026-06-17
Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
- CVE-2026-49081HIGHCVSS 8.2EG 8.22026-06-17
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
- CVE-2026-4916LOWCVSS 2.7EG 2.72026-04-08
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove high…
- CVE-2026-49205MEDIUMCVSS 6.5EG 6.52026-06-18
phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BA…
- CVE-2026-4925MEDIUMCVSS 5.0EG 5.02026-04-01
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. …
- CVE-2026-49258HIGHCVSS 8.8EG 8.82026-06-26
Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h…
- CVE-2026-49274MEDIUMCVSS 5.3EG 5.32026-06-18
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission disabled allowed authenticated users to provide an inaccessible parent page or …
- CVE-2026-49288MEDIUMCVSS 4.3EG 4.32026-06-19
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, as…
- CVE-2026-49291HIGHCVSS 8.1EG 8.12026-06-19
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that…
- CVE-2026-49292LOWEG not assessed2026-07-02
Kiwi TCMS's /init-db/ page renders and responds to requests after first use Kiwi TCMS provides the /init-db/ page as part of its setup mechanism for administrators who prefer a browser instead of the command line. In previous versions of …
- CVE-2026-49326MEDIUMCVSS 6.5EG 6.52026-07-24
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed…
- CVE-2026-49357HIGHCVSS 8.8EG 8.82026-06-19
Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable H…
- CVE-2026-49367HIGHCVSS 8.8EG 8.82026-05-29
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
- CVE-2026-49374HIGHCVSS 7.6EG 7.62026-05-29
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
- CVE-2026-49378MEDIUMCVSS 4.3EG 4.32026-05-29
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
- CVE-2026-49385MEDIUMCVSS 6.5EG 6.52026-05-29
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
- CVE-2026-49394HIGHCVSS 7.1EG 7.12026-07-10
Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue…
- CVE-2026-4949MEDIUMCVSS 4.3EG 4.32026-04-15
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.16.12. This is …
- CVE-2026-4968MEDIUMCVSS 4.3EG 4.32026-03-27
A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The attack may be launched remotely. The ex…
- CVE-2026-4971MEDIUMCVSS 4.3EG 4.32026-03-27
A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been made…
- CVE-2026-49741HIGHCVSS 8.7EG 8.72026-06-09
Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persistence validation and permission checks. Thi…
- CVE-2026-4977MEDIUMCVSS 4.3EG 4.32026-04-10
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to insufficient field-level pe…
- CVE-2026-49775MEDIUMCVSS 6.5EG 6.52026-06-15
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
- CVE-2026-49782MEDIUMCVSS 5.4EG 5.42026-06-02
Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0.
- CVE-2026-49821HIGHCVSS 7.7EG 7.72026-06-10
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's buildermgr controller processed Package CRDs without verifying…
- CVE-2026-49822HIGHCVSS 7.7EG 7.72026-06-10
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a KubernetesWatchTrigger (KWT…
- CVE-2026-4986MEDIUMCVSS 5.3EG 5.32026-06-09
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbit…
- CVE-2026-49948HIGHCVSS 8.1EG 8.12026-06-09
Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only ver…
- CVE-2026-49956MEDIUMCVSS 6.5EG 6.52026-06-09
Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to other profiles by querying the session search endpoint without active-profile filtering. Att…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →