CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,993 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 175 of 180
- CVE-2026-57689MEDIUMCVSS 4.3EG 4.32026-07-02
Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
- CVE-2026-57703MEDIUMCVSS 6.3EG 6.32026-07-23
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
- CVE-2026-57705HIGHCVSS 7.5EG 7.52026-07-13
Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.
- CVE-2026-57717MEDIUMCVSS 6.5EG 6.52026-07-23
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
- CVE-2026-57720MEDIUMCVSS 4.3EG 4.32026-07-01
Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.
- CVE-2026-57721MEDIUMCVSS 5.3EG 5.32026-07-01
Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6.
- CVE-2026-57727HIGHCVSS 7.5EG 7.52026-07-13
Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.
- CVE-2026-57729HIGHCVSS 7.5EG 7.52026-07-13
Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.
- CVE-2026-57730MEDIUMCVSS 4.3EG 4.32026-07-02
Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
- CVE-2026-57731MEDIUMCVSS 6.5EG 6.52026-07-02
Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
- CVE-2026-57740HIGHCVSS 7.1EG 7.12026-07-13
Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through…
- CVE-2026-57746HIGHCVSS 7.1EG 7.12026-07-02
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
- CVE-2026-57750MEDIUMCVSS 5.3EG 5.32026-07-02
Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
- CVE-2026-57760MEDIUMCVSS 5.3EG 5.32026-07-02
Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.
- CVE-2026-57774MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0.
- CVE-2026-57776MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7.
- CVE-2026-57778MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking …
- CVE-2026-57779MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.
- CVE-2026-57781MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MeetingHub: from n/a through <= 1.25.10.
- CVE-2026-57782MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.
- CVE-2026-57797MEDIUMCVSS 4.3EG 4.32026-07-13
Missing Authorization vulnerability in ThemeMove EduMall edumall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EduMall: from n/a through <= 4.5.1.
- CVE-2026-57808MEDIUMCVSS 6.5EG 6.52026-07-23
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
- CVE-2026-57812MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a thr…
- CVE-2026-57830CRITICALCVSS 9.1EG 9.12026-07-13
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
- CVE-2026-57850HIGHCVSS 8.3EG 8.32026-07-10
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options re…
- CVE-2026-57921HIGHCVSS 7.5EG 7.52026-06-26
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
- CVE-2026-57922MEDIUMCVSS 5.3EG 5.32026-06-26
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
- CVE-2026-57923HIGHCVSS 7.5EG 7.52026-06-26
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
- CVE-2026-57925MEDIUMCVSS 5.3EG 5.32026-06-26
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
- CVE-2026-57946LOWCVSS 3.7EG 3.72026-06-29
Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers …
- CVE-2026-57949MEDIUMCVSS 6.5EG 6.52026-06-29
ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by ite…
- CVE-2026-57952MEDIUMCVSS 6.5EG 6.52026-06-29
Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verif…
- CVE-2026-57954MEDIUMCVSS 4.3EG 4.32026-06-29
Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row …
- CVE-2026-58165HIGHCVSS 8.8EG 8.82026-06-30
OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, inclu…
- CVE-2026-58167MEDIUMCVSS 6.5EG 6.52026-06-30
Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) u…
- CVE-2026-58168HIGHCVSS 8.8EG 8.82026-06-30
DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools …
- CVE-2026-58176MEDIUMCVSS 6.5EG 6.52026-06-30
RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the controller declares no class-level or method-level authorization a…
- CVE-2026-58275CRITICALCVSS 10.0EG 10.02026-07-24
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-58279MEDIUMCVSS 6.5EG 6.52026-07-14
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
- CVE-2026-58373MEDIUMCVSS 4.3EG 4.32026-06-30
CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing c…
- CVE-2026-58377HIGHCVSS 8.1EG 8.12026-06-30
JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController …
- CVE-2026-58408MEDIUMCVSS 6.5EG 6.52026-07-13
ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admin/export UI and exfiltrate the entire member directory. The POST /CSVCreateFile.php endpoint generates and streams a CS…
- CVE-2026-58410HIGHCVSS 7.1EG 7.12026-07-13
ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify other families’ records. An authenticated …
- CVE-2026-58448MEDIUMCVSS 6.5EG 6.52026-06-30
yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an …
- CVE-2026-58473CRITICALCVSS 9.1EG 9.12026-07-07
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs…
- CVE-2026-58482MEDIUMCVSS 5.9EG 5.92026-07-20
Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which `ApprovalGate`…
- CVE-2026-58589MEDIUMCVSS 5.4EG 5.42026-07-10
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
- CVE-2026-58590MEDIUMCVSS 5.4EG 5.42026-07-10
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
- CVE-2026-59097MEDIUMCVSS 5.3EG 5.32026-07-02
Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue d…
- CVE-2026-59216CRITICALCVSS 9.0EG 9.02026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the s…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →