CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,627 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 155 of 173
- CVE-2026-34766LOWCVSS 3.3EG 3.32026-04-04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID…
- CVE-2026-3477MEDIUMCVSS 5.3EG 5.32026-04-08
The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. The pzfm_user_request_action_callback() function, registered via the wp_ajax_pzfm_user_request_action action hoo…
- CVE-2026-34782MEDIUMCVSS 4.3EG 4.32026-04-08
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /api/v1/ai_assistance/text_tools/:id was not checking if a user is privileged to use the text tool, resulting in being abl…
- CVE-2026-3480MEDIUMCVSS 6.5EG 6.52026-04-08
The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. The plugin registers an admin_post action hook 'wp-blockade-shortcode-render' that maps to the render_shortcode_preview…
- CVE-2026-34837MEDIUMCVSS 4.3EG 4.32026-04-08
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistance/text_tools/:id contains an authorization failure. Context data (e.g., a group or organization) supplied to be u…
- CVE-2026-3488MEDIUMCVSS 6.5EG 6.52026-04-17
The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including `wp_statistics_get_filters`, `wp_stat…
- CVE-2026-34886HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
- CVE-2026-34892MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.
- CVE-2026-34898HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
- CVE-2026-34899MEDIUMCVSS 5.3EG 5.32026-04-07
Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express …
- CVE-2026-34903MEDIUMCVSS 5.4EG 5.42026-04-07
Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through 2.5.3.
- CVE-2026-34976CRITICALCVSS 10.0EG 10.02026-04-06
Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated. Unlike the similar restore mutat…
- CVE-2026-35033CRITICALCVSS 9.1EG 9.12026-04-14
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The Pars…
- CVE-2026-3506MEDIUMCVSS 5.3EG 5.32026-03-21
The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes …
- CVE-2026-35061MEDIUMCVSS 5.3EG 5.32026-04-17
Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication, revealing sensitive operational imagery.
- CVE-2026-35063HIGHCVSS 8.8EG 8.82026-04-09
OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying their user ID or they can create new accoun…
- CVE-2026-35175MEDIUMCVSS 6.5EG 6.52026-04-06
Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed…
- CVE-2026-35179MEDIUMCVSS 5.3EG 5.32026-04-06
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint …
- CVE-2026-35182HIGHCVSS 8.8EG 8.82026-04-06
Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-use…
- CVE-2026-3524HIGHCVSS 8.8EG 8.82026-04-06
Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API re…
- CVE-2026-35438HIGHCVSS 8.3EG 8.32026-05-12
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
- CVE-2026-35443MEDIUMCVSS 5.3EG 5.32026-06-02
NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` autho…
- CVE-2026-35448LOWCVSS 3.7EG 3.72026-04-06
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint was designed as an …
- CVE-2026-3550MEDIUMCVSS 5.3EG 5.32026-03-20
The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. This is due to missing capability checks on multiple AJAX actions (rockpress_import, rockpress_import_status, rockpress…
- CVE-2026-3552MEDIUMCVSS 4.3EG 4.32026-07-11
The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capability …
- CVE-2026-35552HIGHCVSS 8.1EG 8.12026-07-08
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, th…
- CVE-2026-35561HIGHCVSS 7.4EG 7.42026-04-03
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protecti…
- CVE-2026-35598MEDIUMCVSS 4.3EG 4.32026-04-10
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task…
- CVE-2026-35606HIGHCVSS 7.5EG 7.52026-04-07
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in http/resource.go returns full text file content without che…
- CVE-2026-35620MEDIUMCVSS 5.4EG 5.42026-04-10
OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner command-authorized senders to change owner-only session delivery policy settings…
- CVE-2026-35621MEDIUMCVSS 6.5EG 6.52026-04-10
OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for internal callers, allowing operator.write-scoped clients to mutate channel authorization po…
- CVE-2026-35630HIGHCVSS 8.0EG 8.02026-05-29
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin a…
- CVE-2026-35631MEDIUMCVSS 6.5EG 6.52026-04-09
OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin privileges can execute mutating control-plane actions by directly invoking…
- CVE-2026-35660HIGHCVSS 8.1EG 8.12026-04-10
OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint that allows callers with operator.write permission to reset admin sessions. Attackers with operator.write privileges can i…
- CVE-2026-35662MEDIUMCVSS 4.3EG 4.32026-04-10
OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond their authorized scope. Attackers can exploit this by using the send action to com…
- CVE-2026-3567MEDIUMCVSS 5.3EG 5.32026-03-21
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to…
- CVE-2026-3569MEDIUMCVSS 5.3EG 5.32026-04-24
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions_read() permission callback unconditionally…
- CVE-2026-3570MEDIUMCVSS 5.3EG 5.32026-03-21
The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global s…
- CVE-2026-3571MEDIUMCVSS 6.5EG 6.52026-04-04
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and includin…
- CVE-2026-3581MEDIUMCVSS 5.3EG 5.32026-04-16
The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This mak…
- CVE-2026-3595MEDIUMCVSS 5.3EG 5.32026-04-16
The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to the plugin registering a REST API route at POST /wp-json/InkXEProductDesignerLite/customer/…
- CVE-2026-3596CRITICALCVSS 9.8EG 9.82026-04-16
The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopriv_install-imprint') that maps to the in…
- CVE-2026-3601MEDIUMCVSS 4.3EG 4.32026-05-05
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it p…
- CVE-2026-3614HIGHCVSS 8.8EG 8.82026-04-16
The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 10.8.1 due to a missing capability check on the `wp_ajax_acymailing_router` AJAX handler. This makes it possible fo…
- CVE-2026-3637MEDIUMCVSS 4.3EG 4.32026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their…
- CVE-2026-3640MEDIUMCVSS 5.3EG 5.32026-06-19
The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin registers a REST API webhook endpoint at /wp-json/strabl/webhook/order with a permission_ca…
- CVE-2026-3642MEDIUMCVSS 5.3EG 5.32026-04-15
The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builder_update_field_data() AJAX handler lacks any capability checks (current_user_can()) or n…
- CVE-2026-3645MEDIUMCVSS 5.3EG 5.32026-03-21
The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.1. The save_config() function, which handles the 'punnel_save_config' AJAX action, lacks any capabili…
- CVE-2026-3646MEDIUMCVSS 5.3EG 5.32026-04-08
The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization…
- CVE-2026-3649MEDIUMCVSS 5.3EG 5.32026-04-15
The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.0. The katalogportal_popup_shortcode() function is registered as an AJAX handler via wp_ajax_katalogportal_short…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →