CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
10,777 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 1 of 216
- CVE-2022-0543CRITICALCVSS 10.0EG 10.0⚠ KEV2022-02-18
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
- CVE-2026-84869CRITICALCVSS 9.9EG 9.9⚠ KEV2026-09-08
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
- CVE-2024-57726CRITICALCVSS 9.9EG 9.9⚠ KEV2025-01-15
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
- CVE-2021-39226CRITICALCVSS 9.8EG 9.8⚠ KEV2021-10-05
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /ap…
- CVE-2025-6205CRITICALCVSS 9.1EG 9.1⚠ KEV2025-08-04
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.
- CVE-2023-52163CRITICALCVSS 8.8EG 9.0⚠ KEV2025-02-03
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- CVE-2025-20362CRITICALCVSS 8.6EG 9.0⚠ KEV2025-09-25
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause u…
- CVE-2022-0492CRITICALCVSS 7.8EG 9.0⚠ KEV2022-03-03
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges a…
- CVE-2021-30713CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-08
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exp…
- CVE-2025-40602CRITICALCVSS 6.6EG 9.0⚠ KEV2025-12-18
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
- CVE-2021-37976CRITICALCVSS 6.5EG 9.0⚠ KEV2021-10-08
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2020-8193CRITICALCVSS 6.5EG 9.0⚠ KEV2020-07-10
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to cer…
- CVE-2021-30657CRITICALCVSS 5.5EG 9.0⚠ KEV2021-09-08
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may …
- CVE-2021-26085CRITICALCVSS 5.3EG 9.0⚠ KEV2021-08-03
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from v…
- CVE-2020-8196CRITICALCVSS 4.3EG 9.0⚠ KEV2020-07-10
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information dis…
- CVE-2026-101000CRITICALCVSS 10.0EG 10.02026-09-28
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes…
- CVE-2026-97360CRITICALCVSS 10.0EG 10.02026-09-24
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside th…
- CVE-2026-77244CRITICALCVSS 10.0EG 10.02026-09-22
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to th…
- CVE-2026-65381CRITICALCVSS 10.0EG 10.02026-09-14
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious app ma…
- CVE-2026-81648CRITICALCVSS 10.0EG 10.02026-09-13
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on th…
- CVE-2026-77770CRITICALCVSS 10.0EG 10.02026-09-10
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor…
- CVE-2026-65667CRITICALCVSS 10.0EG 10.02026-08-06
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-48168CRITICALCVSS 10.0EG 10.02026-08-05
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block wi…
- CVE-2026-66012CRITICALCVSS 10.0EG 10.02026-07-25
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, inc…
- CVE-2026-27604CRITICALCVSS 10.0EG 10.02026-06-23
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` end…
- CVE-2026-0092CRITICALCVSS 10.0EG 10.02026-06-17
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex…
- CVE-2026-44329CRITICALCVSS 10.0EG 10.02026-05-27
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on the SBI can …
- CVE-2026-44327CRITICALCVSS 10.0EG 10.02026-05-27
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the O…
- CVE-2026-33712CRITICALCVSS 10.0EG 10.02026-05-22
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a cust…
- CVE-2026-2031CRITICALCVSS 10.0EG 10.02026-05-15
An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute a…
- CVE-2026-41679CRITICALCVSS 10.0EG 10.02026-04-23
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instanc…
- CVE-2026-34976CRITICALCVSS 10.0EG 10.02026-04-06
Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated. Unlike the similar restore mutat…
- CVE-2025-30416CRITICALCVSS 10.0EG 10.02026-02-20
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
- CVE-2025-45854CRITICALCVSS 10.0EG 10.02025-06-03
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
- CVE-2025-46348CRITICALCVSS 10.0EG 10.02025-04-29
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could …
- CVE-2025-26853CRITICALCVSS 10.0EG 10.02025-03-20
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
- CVE-2025-22612CRITICALCVSS 10.0EG 10.02025-01-24
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify …
- CVE-2025-22609CRITICALCVSS 10.0EG 10.02025-01-24
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify in…
- CVE-2024-52416CRITICALCVSS 10.0EG 10.02024-11-16
Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through <= 2.2.
- CVE-2024-6500CRITICALCVSS 10.0EG 10.02024-08-17
The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (…
- CVE-2024-6071CRITICALCVSS 10.0EG 10.02024-06-27
PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.
- CVE-2024-33566CRITICALCVSS 10.0EG 10.02024-04-29
Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.
- CVE-2024-2086CRITICALCVSS 10.0EG 10.02024-03-30
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and …
- CVE-2020-26824CRITICALCVSS 10.0EG 10.02020-11-10
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integrity and availabilit…
- CVE-2020-26823CRITICALCVSS 10.0EG 10.02020-11-10
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Service, this has an impact to the integrity…
- CVE-2020-26822CRITICALCVSS 10.0EG 10.02020-11-10
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and …
- CVE-2020-26821CRITICALCVSS 10.0EG 10.02020-11-10
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of th…
- CVE-2020-9411CRITICALCVSS 10.0EG 10.02020-06-09
The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vulnerability that theoretically allows an attacker to perform unauthorized network file transfers to and from the file s…
- CVE-2026-58275CRITICALCVSS 9.8EG 10.02026-07-24
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-82041CRITICALCVSS 9.9EG 9.92026-10-02
UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied be…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →