CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,990 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 173 of 180
- CVE-2026-55542MEDIUMCVSS 4.3EG 4.32026-06-23
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obta…
- CVE-2026-55544HIGHCVSS 7.6EG 7.62026-07-20
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The applicat…
- CVE-2026-55548MEDIUMCVSS 4.3EG 4.32026-07-16
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omit…
- CVE-2026-55550HIGHCVSS 7.1EG 7.12026-07-20
NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, and deletion to `manager` and `ad…
- CVE-2026-55628MEDIUMCVSS 5.5EG 5.52026-07-01
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to pat…
- CVE-2026-55638HIGHCVSS 8.6EG 8.62026-07-10
9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. A remote unauthenticate…
- CVE-2026-5572MEDIUMCVSS 4.3EG 4.32026-04-05
A security flaw has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has b…
- CVE-2026-5574CRITICALCVSS 9.1EG 9.12026-04-05
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to missing authorization. The a…
- CVE-2026-55762HIGHCVSS 8.1EG 8.12026-06-24
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerprint REST endpoint enforces authentication (authRequired: true) but …
- CVE-2026-55838MEDIUMCVSS 4.3EG 4.32026-06-26
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin…
- CVE-2026-56023MEDIUMCVSS 5.4EG 5.42026-06-25
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
- CVE-2026-56025HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
- CVE-2026-56038HIGHCVSS 8.8EG 8.82026-06-26
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
- CVE-2026-56061HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
- CVE-2026-56063HIGHCVSS 8.3EG 8.32026-06-26
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
- CVE-2026-56104HIGHCVSS 8.2EG 8.22026-06-22
Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownersh…
- CVE-2026-56115HIGHCVSS 8.8EG 8.82026-06-23
Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/a…
- CVE-2026-56213MEDIUMCVSS 5.3EG 5.32026-06-20
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgREST RPC, allowing unauthenticated attackers to insert arbitrary rows into version_meta for a…
- CVE-2026-5624MEDIUMCVSS 4.3EG 4.32026-04-06
A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit ha…
- CVE-2026-56250HIGHCVSS 7.5EG 7.52026-07-08
Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbitrary R2 bundle objects. Attackers can patch r2_path to point to victim objects, soft-delet…
- CVE-2026-5626MEDIUMCVSS 4.3EG 4.32026-07-29
The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated …
- CVE-2026-56279HIGHCVSS 7.5EG 7.52026-07-10
Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated attackers can supply arbitrary user UU…
- CVE-2026-56280HIGHCVSS 7.1EG 7.12026-06-22
Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running native builds. The endpoint registers an abort listener on the SSE stream that unconditio…
- CVE-2026-56341HIGHCVSS 7.5EG 7.52026-06-20
AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attacke…
- CVE-2026-56384MEDIUMCVSS 4.3EG 4.32026-06-21
Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive pre…
- CVE-2026-56396HIGHCVSS 8.8EG 8.82026-06-21
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_s…
- CVE-2026-56402MEDIUMCVSS 6.5EG 6.52026-06-23
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like…
- CVE-2026-56423HIGHCVSS 8.8EG 8.82026-06-22
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authoriz…
- CVE-2026-56424HIGHCVSS 8.8EG 8.82026-06-22
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged auth…
- CVE-2026-56668HIGHCVSS 8.1EG 8.12026-07-10
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client o…
- CVE-2026-56695MEDIUMCVSS 6.5EG 6.52026-06-23
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots …
- CVE-2026-56696MEDIUMCVSS 5.4EG 5.42026-06-23
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious con…
- CVE-2026-56742HIGHCVSS 8.9EG 8.92026-07-15
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Ser…
- CVE-2026-56767HIGHCVSS 8.8EG 8.82026-06-25
Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Goo…
- CVE-2026-56768HIGHCVSS 8.8EG 8.82026-06-25
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a…
- CVE-2026-56773HIGHCVSS 8.8EG 8.82026-06-26
Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and t…
- CVE-2026-5693MEDIUMCVSS 5.3EG 5.32026-05-12
The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and in…
- CVE-2026-57205MEDIUMCVSS 4.3EG 4.32026-07-16
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoint…
- CVE-2026-57206HIGHCVSS 8.6EG 8.62026-07-16
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, includi…
- CVE-2026-57221MEDIUMCVSS 5.0EG 5.02026-07-10
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user …
- CVE-2026-57285MEDIUMCVSS 4.3EG 4.32026-06-24
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configurati…
- CVE-2026-57286MEDIUMCVSS 4.3EG 4.32026-06-24
A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revisio…
- CVE-2026-57291MEDIUMCVSS 5.4EG 5.42026-06-24
Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another meth…
- CVE-2026-57293MEDIUMCVSS 4.3EG 4.32026-06-24
An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of …
- CVE-2026-57294MEDIUMCVSS 5.4EG 5.42026-06-24
A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through ano…
- CVE-2026-57297MEDIUMCVSS 4.3EG 4.32026-06-24
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and…
- CVE-2026-57299MEDIUMCVSS 4.3EG 4.32026-06-24
Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.
- CVE-2026-57300MEDIUMCVSS 4.3EG 4.32026-06-24
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.
- CVE-2026-57304MEDIUMCVSS 5.4EG 5.42026-06-24
A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username and password.
- CVE-2026-57307MEDIUMCVSS 4.2EG 4.22026-06-24
A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through …
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →