CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,990 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 172 of 180
- CVE-2026-53820MEDIUMCVSS 6.6EG 6.62026-06-12
OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated callers to bypass intended command restrictions. Attackers can reach the affected bundled MCP …
- CVE-2026-53821HIGHCVSS 8.8EG 8.82026-06-12
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can obtain cached operat…
- CVE-2026-53844MEDIUMCVSS 6.5EG 6.52026-06-16
OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guard…
- CVE-2026-53850MEDIUMCVSS 5.5EG 5.52026-06-16
OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command …
- CVE-2026-53851MEDIUMCVSS 5.3EG 5.32026-06-16
OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended agent processing by sending reactio…
- CVE-2026-53866HIGHCVSS 8.1EG 8.12026-06-16
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through…
- CVE-2026-5387CRITICALCVSS 9.3EG 9.32026-04-15
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modi…
- CVE-2026-54004MEDIUMCVSS 6.3EG 6.32026-06-18
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media …
- CVE-2026-54005HIGHCVSS 7.1EG 7.12026-06-18
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know or guess page IDs or UUIDs to retrieve page information, in…
- CVE-2026-54010HIGHCVSS 8.3EG 8.32026-06-17
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own chat message without checking whether the…
- CVE-2026-54012HIGHCVSS 7.1EG 7.12026-06-17
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can create, update, or import workspace models store arbitrary meta.knowledge entries on their mo…
- CVE-2026-54019MEDIUMCVSS 6.5EG 6.52026-06-17
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-level ACL checks, but the patch can still be bypassed when Milvus multitenancy mode is enabled. …
- CVE-2026-54027MEDIUMCVSS 6.5EG 6.52026-06-25
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool_resources (e.g., context, execute_code)…
- CVE-2026-54029MEDIUMCVSS 6.5EG 6.52026-06-25
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messages. The validateMes…
- CVE-2026-54052CRITICALCVSS 9.9EG 9.92026-07-14
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version …
- CVE-2026-54190MEDIUMCVSS 6.5EG 6.52026-06-16
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
- CVE-2026-5427MEDIUMCVSS 5.3EG 5.32026-04-17
The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability checks in the kubio_rest_pre_insert_import_assets() function, which is hooked to the rest_p…
- CVE-2026-54322HIGHCVSS 7.7EG 7.72026-06-16
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization role update and delete endpoints authorized the caller as an owner of the organization nam…
- CVE-2026-54329HIGHCVSS 7.7EG 7.72026-06-23
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in …
- CVE-2026-54415HIGHCVSS 8.1EG 8.12026-06-17
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over n…
- CVE-2026-54475HIGHCVSS 7.5EG 7.52026-06-30
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be brok…
- CVE-2026-54568MEDIUMCVSS 4.3EG 4.32026-07-16
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id …
- CVE-2026-54628HIGHCVSS 8.6EG 8.62026-07-14
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode ## Summary Anyquery's `server` mode does not restrict outbound HTTP requests initiated by its built-in SQLite virtual table modules …
- CVE-2026-54629HIGHCVSS 7.5EG 7.52026-07-14
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode ## Summary Anyquery's `server` mode lacks input sanitization and access control over its built-in SQLite virtual table modules (e.g., `csv_reader…
- CVE-2026-5464HIGHCVSS 7.2EG 7.22026-04-23
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due t…
- CVE-2026-54695MEDIUMCVSS 6.5EG 6.52026-06-18
Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections …
- CVE-2026-54719HIGHCVSS 7.5EG 7.52026-07-28
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauth…
- CVE-2026-54802HIGHCVSS 7.5EG 7.52026-06-17
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
- CVE-2026-54810HIGHCVSS 7.5EG 7.52026-06-17
Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexi XPay: from n/a through 8.3.1.
- CVE-2026-54828HIGHCVSS 7.5EG 7.52026-06-25
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
- CVE-2026-54830HIGHCVSS 7.5EG 7.52026-06-25
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
- CVE-2026-54832HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
- CVE-2026-54835HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
- CVE-2026-54837HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions.
- CVE-2026-54840HIGHCVSS 7.3EG 7.32026-06-26
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
- CVE-2026-54842HIGHCVSS 8.1EG 8.12026-06-25
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly... Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This …
- CVE-2026-54844HIGHCVSS 7.5EG 7.52026-06-25
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
- CVE-2026-54846HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions.
- CVE-2026-54847HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
- CVE-2026-5488MEDIUMCVSS 5.3EG 5.32026-04-24
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and res…
- CVE-2026-5502MEDIUMCVSS 5.3EG 5.32026-04-17
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing authorization check in the tutor_update_c…
- CVE-2026-55052HIGHCVSS 8.8EG 8.82026-07-14
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-55188HIGHCVSS 8.2EG 8.22026-06-26
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replica…
- CVE-2026-55189HIGHCVSS 7.7EG 7.72026-06-26
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM aut…
- CVE-2026-55417MEDIUMCVSS 6.9EG 6.92026-07-07
Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile option, visiting their profile HTML route (`/username`) correctly returns 404. However, the `/…
- CVE-2026-55432MEDIUMCVSS 5.4EG 5.42026-07-06
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `Ma…
- CVE-2026-55433MEDIUMCVSS 5.4EG 5.42026-07-06
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on th…
- CVE-2026-55440MEDIUMCVSS 6.5EG 6.52026-07-16
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py wit…
- CVE-2026-55476MEDIUMCVSS 4.3EG 4.32026-07-10
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an a…
- CVE-2026-55518CRITICALCVSS 9.6EG 9.62026-06-17
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new path, but the actua…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →