CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,996 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 176 of 180
- CVE-2026-58590MEDIUMCVSS 5.4EG 5.42026-07-10
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
- CVE-2026-59097MEDIUMCVSS 5.3EG 5.32026-07-02
Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue d…
- CVE-2026-59216CRITICALCVSS 9.0EG 9.02026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the s…
- CVE-2026-59217MEDIUMCVSS 4.3EG 4.32026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded files to a target knowledge base without applying the write…
- CVE-2026-59225MEDIUMCVSS 6.3EG 6.32026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through tas…
- CVE-2026-59226MEDIUMCVSS 4.3EG 4.32026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automation…
- CVE-2026-59227MEDIUMCVSS 5.4EG 5.42026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required only a verified account and did not enforce the global image-edit switch or the per-user ima…
- CVE-2026-59255HIGHCVSS 7.1EG 7.12026-07-15
BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens c…
- CVE-2026-59262MEDIUMCVSS 6.5EG 6.52026-07-08
AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines. Attackers can supply arbitrary document GUIDs …
- CVE-2026-5944HIGHCVSS 8.2EG 8.22026-04-28
An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deploym…
- CVE-2026-59509CRITICALCVSS 9.2EG 9.22026-07-05
An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression…
- CVE-2026-59522MEDIUMCVSS 6.5EG 6.52026-07-23
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
- CVE-2026-59523MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a thr…
- CVE-2026-59529HIGHCVSS 7.5EG 7.52026-07-27
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
- CVE-2026-59530HIGHCVSS 7.5EG 7.52026-07-27
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
- CVE-2026-59534HIGHCVSS 7.5EG 7.52026-07-27
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
- CVE-2026-59535HIGHCVSS 7.3EG 7.32026-07-27
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
- CVE-2026-59536HIGHCVSS 7.5EG 7.52026-07-27
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
- CVE-2026-59547HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
- CVE-2026-59557MEDIUMCVSS 6.5EG 6.52026-07-27
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
- CVE-2026-59560MEDIUMCVSS 6.5EG 6.52026-07-27
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
- CVE-2026-59677MEDIUMCVSS 6.8EG 6.82026-07-23
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils …
- CVE-2026-59690HIGHCVSS 8.0EG 8.02026-07-27
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged adminis…
- CVE-2026-59704HIGHCVSS 7.1EG 7.12026-07-07
Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can supply arbitrary video IDs to read sensitive …
- CVE-2026-59708HIGHCVSS 7.5EG 7.52026-07-07
The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retriev…
- CVE-2026-59709MEDIUMCVSS 4.3EG 4.32026-07-07
Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attacke…
- CVE-2026-59796HIGHCVSS 8.1EG 8.12026-07-10
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
- CVE-2026-59805MEDIUMCVSS 6.5EG 6.52026-07-08
Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_access …
- CVE-2026-59853MEDIUMCVSS 6.5EG 6.52026-07-09
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage…
- CVE-2026-60118MEDIUMCVSS 5.3EG 5.32026-07-14
Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without aut…
- CVE-2026-60119MEDIUMCVSS 5.4EG 5.42026-07-14
Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding a malicious event title containing the <…
- CVE-2026-60124MEDIUMCVSS 5.3EG 5.32026-07-08
An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results…
- CVE-2026-60712MEDIUMCVSS 6.5EG 6.52026-07-21
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with lo…
- CVE-2026-60953HIGHCVSS 8.1EG 8.12026-07-21
Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low pr…
- CVE-2026-6109MEDIUMCVSS 4.3EG 4.32026-04-12
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manip…
- CVE-2026-61267HIGHCVSS 7.3EG 7.32026-07-21
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated …
- CVE-2026-61440MEDIUMCVSS 6.5EG 6.52026-07-15
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member p…
- CVE-2026-61441MEDIUMCVSS 6.5EG 6.52026-07-10
PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-select…
- CVE-2026-61442HIGHCVSS 7.1EG 7.12026-07-11
PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created rec…
- CVE-2026-6145MEDIUMCVSS 5.3EG 5.32026-05-14
The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=crea…
- CVE-2026-61718MEDIUMCVSS 5.4EG 5.42026-07-16
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ URL prefix, so routes in src/ui/app/routes/cache…
- CVE-2026-61943HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
- CVE-2026-61952MEDIUMCVSS 4.9EG 4.92026-07-13
Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Pro…
- CVE-2026-61954HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
- CVE-2026-61958MEDIUMCVSS 5.4EG 5.42026-07-13
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: f…
- CVE-2026-61968MEDIUMCVSS 5.4EG 5.42026-07-13
Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 3.1.2.
- CVE-2026-61972MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
- CVE-2026-61973MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
- CVE-2026-61983MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.
- CVE-2026-61985MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →