CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,627 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 151 of 173
- CVE-2026-27433MEDIUMCVSS 6.5EG 6.52026-07-02
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
- CVE-2026-27435MEDIUMCVSS 5.3EG 5.32026-07-01
Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.
- CVE-2026-27604CRITICALCVSS 10.0EG 10.02026-06-23
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` end…
- CVE-2026-27608HIGHCVSS 8.1EG 8.12026-02-25
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to…
- CVE-2026-27672MEDIUMCVSS 4.3EG 4.32026-04-14
The Material Master application does not enforce authorization checks for authenticated users when executing reports, resulting in the disclosure of sensitive information. This vulnerability has a low impact on confidentiality and does not…
- CVE-2026-27673MEDIUMCVSS 4.9EG 4.92026-04-14
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Conf…
- CVE-2026-27676MEDIUMCVSS 4.3EG 4.32026-04-14
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability resul…
- CVE-2026-27677MEDIUMCVSS 6.5EG 6.52026-04-14
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could update and delete child entities via OData services without proper authorization. This vulnerability has a high impact on …
- CVE-2026-27678MEDIUMCVSS 6.5EG 6.52026-04-14
Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has …
- CVE-2026-27679MEDIUMCVSS 6.5EG 6.52026-04-14
Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has…
- CVE-2026-27688MEDIUMCVSS 5.0EG 5.02026-03-10
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary pr…
- CVE-2026-27708HIGHCVSS 7.1EG 7.12026-06-24
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authent…
- CVE-2026-27769LOWCVSS 2.7EG 2.72026-04-15
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed…
- CVE-2026-27771HIGHCVSS 8.2EG 8.22026-07-03
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
- CVE-2026-27783MEDIUMCVSS 4.3EG 4.32026-06-16
Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
- CVE-2026-27833HIGHCVSS 7.5EG 7.52026-04-03
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing hi…
- CVE-2026-28038MEDIUMCVSS 6.5EG 6.52026-03-05
Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Pa…
- CVE-2026-28070MEDIUMCVSS 5.3EG 5.32026-03-19
Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP eMember: from n/a through v10.2.2.
- CVE-2026-28071MEDIUMCVSS 6.3EG 6.32026-03-05
Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pixfort Core: from n/a through <= 3.2.22.
- CVE-2026-28076HIGHCVSS 7.5EG 7.52026-03-05
Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Guff: from n/a through <= 1.0.1.
- CVE-2026-28080MEDIUMCVSS 4.3EG 4.32026-03-06
Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO PRO: from n/a through 3.0.95.
- CVE-2026-28104MEDIUMCVSS 6.5EG 6.52026-03-05
Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Site Suggest: from n/a through <= 1.3.9.
- CVE-2026-2819MEDIUMCVSS 6.3EG 6.32026-02-20
A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to mi…
- CVE-2026-2826MEDIUMCVSS 4.3EG 4.32026-04-04
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the `…
- CVE-2026-28309CRITICALCVSS 9.1EG 9.12026-07-21
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
- CVE-2026-28310CRITICALCVSS 9.1EG 9.12026-07-21
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
- CVE-2026-28380MEDIUMCVSS 6.5EG 6.52026-05-13
Any Editor could delete any snapshot, even if they have no access to read or write them.
- CVE-2026-28515HIGHCVSS 8.8EG 8.82026-02-27
openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing applicati…
- CVE-2026-28557MEDIUMCVSS 6.5EG 6.52026-02-28
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforo_synch_roles AJAX handler. Attackers access the usergroups admin page, access…
- CVE-2026-28573MEDIUMCVSS 5.5EG 5.52026-06-18
In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2026-28587MEDIUMCVSS 5.5EG 5.52026-06-17
In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User int…
- CVE-2026-28615HIGHCVSS 7.8EG 7.82026-06-17
In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex…
- CVE-2026-2890HIGHCVSS 7.5EG 7.52026-03-13
The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment reco…
- CVE-2026-2899MEDIUMCVSS 6.5EG 6.52026-03-05
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce verification and capa…
- CVE-2026-2900LOWCVSS 2.7EG 2.72026-05-14
GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authen…
- CVE-2026-2941HIGHCVSS 8.8EG 8.82026-03-21
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. T…
- CVE-2026-29515CRITICALCVSS 9.8EG 9.82026-03-11
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinati…
- CVE-2026-2992HIGHCVSS 8.2EG 8.22026-03-18
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, an…
- CVE-2026-3045HIGHCVSS 7.5EG 7.52026-03-13
The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a no…
- CVE-2026-3056MEDIUMCVSS 4.3EG 4.32026-03-04
The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `seraph_accel_api` AJAX action with `fn=LogClear` in all versions up to, and including, 2.28.14. T…
- CVE-2026-3072MEDIUMCVSS 4.3EG 4.32026-03-05
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes …
- CVE-2026-30950HIGHCVSS 7.1EG 7.12026-05-18
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attac…
- CVE-2026-3098MEDIUMCVSS 6.5EG 6.52026-03-27
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level acces…
- CVE-2026-3117MEDIUMCVSS 6.5EG 6.52026-05-18
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab…
- CVE-2026-31241MEDIUMCVSS 6.5EG 6.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g…
- CVE-2026-31242CRITICALCVSS 9.1EG 9.12026-05-12
The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that triggers a reset operation, …
- CVE-2026-31243MEDIUMCVSS 6.5EG 6.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that trigger…
- CVE-2026-31244MEDIUMCVSS 6.5EG 6.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated users to delete arbitrary memory records without verifying their…
- CVE-2026-31245MEDIUMCVSS 5.3EG 5.32026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or p…
- CVE-2026-31266HIGHCVSS 7.3EG 7.32026-05-27
Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →