CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,997 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 178 of 180
- CVE-2026-65484MEDIUMCVSS 6.3EG 6.32026-07-23
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
- CVE-2026-65485MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
- CVE-2026-65486MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
- CVE-2026-65487MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
- CVE-2026-65489MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
- CVE-2026-65491MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
- CVE-2026-65495HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
- CVE-2026-65499MEDIUMCVSS 6.5EG 6.52026-07-23
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
- CVE-2026-65500HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
- CVE-2026-65506MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
- CVE-2026-65524MEDIUMCVSS 4.3EG 4.32026-07-23
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
- CVE-2026-65525MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
- CVE-2026-65529MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
- CVE-2026-65530MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
- CVE-2026-65531MEDIUMCVSS 4.8EG 4.82026-07-23
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
- CVE-2026-65537MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
- CVE-2026-65567MEDIUMCVSS 5.3EG 5.32026-07-27
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
- CVE-2026-65568MEDIUMCVSS 5.0EG 5.02026-07-27
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
- CVE-2026-6589MEDIUMCVSS 4.3EG 4.32026-04-20
A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. …
- CVE-2026-65895HIGHCVSS 8.5EG 8.52026-07-23
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can di…
- CVE-2026-65916HIGHCVSS 8.1EG 8.12026-07-23
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send c…
- CVE-2026-65922HIGHCVSS 5.4EG 7.12026-07-27
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity …
- CVE-2026-66012CRITICALCVSS 10.0EG 10.02026-07-25
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, inc…
- CVE-2026-66027HIGHCVSS 8.3EG 8.32026-07-24
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account i…
- CVE-2026-66442MEDIUMCVSS 5.4EG 5.42026-07-27
Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
- CVE-2026-66473HIGHCVSS 7.5EG 7.52026-07-27
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
- CVE-2026-66477MEDIUMCVSS 5.3EG 5.32026-07-27
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
- CVE-2026-6663MEDIUMCVSS 4.8EG 4.82026-05-12
The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints (gwd-backup.php and gwd-logs.php) not v…
- CVE-2026-6667MEDIUMCVSS 4.3EG 4.32026-05-09
PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have b…
- CVE-2026-66723HIGHCVSS 7.0EG 7.02026-07-29
MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for incoming requests, allowing an unauthenticated remote attacker to send…
- CVE-2026-66724MEDIUMCVSS 5.3EG 5.32026-07-29
MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to t…
- CVE-2026-66750MEDIUMCVSS 4.3EG 4.32026-07-28
Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room me…
- CVE-2026-66751MEDIUMCVSS 5.4EG 5.42026-07-28
Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers…
- CVE-2026-6689MEDIUMCVSS 4.3EG 4.32026-06-12
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation (the check was only applied on update…
- CVE-2026-6703MEDIUMCVSS 4.3EG 4.32026-04-21
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized …
- CVE-2026-6706MEDIUMCVSS 6.5EG 6.52026-04-28
Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.…
- CVE-2026-6708MEDIUMCVSS 5.3EG 5.32026-05-12
The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability check on a REST API endpoint registered wit…
- CVE-2026-6709MEDIUMCVSS 4.3EG 4.32026-05-12
The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.1.2. This is due to a missing capability check and missing nonce verification in the save_settings() fun…
- CVE-2026-67344MEDIUMCVSS 4.3EG 4.32026-08-01
ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocume…
- CVE-2026-67527HIGHCVSS 7.6EG 7.62026-07-30
OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with edit_work_packages but without manage_file_links to resolve…
- CVE-2026-67529MEDIUMCVSS 4.3EG 4.32026-07-30
OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _links.workPackage.href through associated_resource in modules/…
- CVE-2026-6792MEDIUMCVSS 6.5EG 6.52026-07-21
Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 before 5.542.0.
- CVE-2026-6798MEDIUMCVSS 5.3EG 5.32026-06-19
The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an…
- CVE-2026-6803MEDIUMCVSS 5.3EG 5.32026-07-11
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions register…
- CVE-2026-6804MEDIUMCVSS 5.3EG 5.32026-07-11
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an …
- CVE-2026-6834MEDIUMCVSS 6.5EG 6.52026-04-22
The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method.
- CVE-2026-68585MEDIUMCVSS 5.8EG 5.82026-08-03
SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous …
- CVE-2026-68586HIGHCVSS 8.6EG 8.62026-08-03
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publi…
- CVE-2026-68587HIGHCVSS 8.6EG 8.62026-08-03
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access c…
- CVE-2026-6883LOWCVSS 2.6EG 2.62026-05-14
GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to i…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →