CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,628 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 160 of 173
- CVE-2026-41498LOWCVSS 3.3EG 3.32026-05-08
Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity…
- CVE-2026-4162HIGHCVSS 7.1EG 7.12026-04-10
The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible f…
- CVE-2026-41658MEDIUMCVSS 6.5EG 6.52026-05-07
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces authorization for destructive operations (delete, retire, reinstate) only in the UI layer by conditionally rendering buttons.…
- CVE-2026-41679CRITICALCVSS 10.0EG 10.02026-04-23
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instanc…
- CVE-2026-42051MEDIUMCVSS 4.3EG 4.32026-05-09
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks license data and installed version to authenticated users. This issue has been patched in versions 4.9.0 and 5.4.0.
- CVE-2026-42069MEDIUMCVSS 6.5EG 6.52026-05-09
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
- CVE-2026-42071HIGHCVSS 7.2EG 7.22026-05-28
Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to download attachments on private bugnote…
- CVE-2026-42083HIGHCVSS 8.2EG 8.22026-05-27
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI. In NewServer…
- CVE-2026-42137MEDIUMCVSS 6.5EG 6.52026-05-09
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4…
- CVE-2026-42174MEDIUMCVSS 4.3EG 4.32026-05-09
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
- CVE-2026-42226HIGHCVSS 7.5EG 7.52026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify whether the authenticated caller was authorized to use a supplied credential reference. An auth…
- CVE-2026-42228MEDIUMCVSS 6.5EG 6.52026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized …
- CVE-2026-42297HIGHCVSS 8.3EG 8.32026-05-09
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's ConfigMap-backed provider (server/sync/sync_cm.go) performs zer…
- CVE-2026-42317HIGHCVSS 7.0EG 7.02026-06-03
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgr…
- CVE-2026-42318HIGHCVSS 7.0EG 7.02026-06-03
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive…
- CVE-2026-42320MEDIUMCVSS 5.9EG 5.92026-06-03
GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
- CVE-2026-42337MEDIUMCVSS 5.3EG 5.32026-05-26
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The endpoint uses application_id from the URL …
- CVE-2026-42377HIGHCVSS 7.3EG 7.32026-04-29
Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0.
- CVE-2026-42412MEDIUMCVSS 6.5EG 6.52026-04-29
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.
- CVE-2026-42433MEDIUMCVSS 6.5EG 6.52026-05-05
OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can exploit insufficient access controls to…
- CVE-2026-42436HIGHCVSS 7.7EG 7.72026-05-05
OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab routes that fail to consistently validate the final browser target after navigation. Authenticated callers can bypass SSRF…
- CVE-2026-42439HIGHCVSS 8.5EG 8.52026-05-05
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Attackers can bypass configured browser SSRF policy protections by exploiting the /tabs/action…
- CVE-2026-42461HIGHCVSS 7.5EG 7.52026-05-09
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/templates* in Arcane's Huma backend are registered without any Security requirement, allowing any …
- CVE-2026-42519MEDIUMCVSS 4.3EG 4.32026-04-29
A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.
- CVE-2026-42522MEDIUMCVSS 4.3EG 4.32026-04-29
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.
- CVE-2026-42541MEDIUMCVSS 4.3EG 4.32026-05-12
Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyGroup create permissions (which isn't the default) can craft a policy that makes use of the can_i host callback. The cal…
- CVE-2026-42569CRITICALCVSS 9.4EG 9.42026-05-09
phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been patched in version 7.0.6.
- CVE-2026-4261HIGHCVSS 8.8EG 8.82026-03-21
The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_role' meta through the 'save_extra_user_…
- CVE-2026-42613CRITICALCVSS 9.4EG 9.42026-05-11
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without server-side validation. When registrati…
- CVE-2026-42640MEDIUMCVSS 6.5EG 6.52026-06-15
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.
- CVE-2026-42642MEDIUMCVSS 5.3EG 5.32026-04-29
Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5.
- CVE-2026-42648MEDIUMCVSS 4.3EG 4.32026-04-29
Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22.
- CVE-2026-42651MEDIUMCVSS 6.3EG 6.32026-06-15
Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions.
- CVE-2026-42659MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.
- CVE-2026-42664HIGHCVSS 8.2EG 8.22026-06-15
Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions.
- CVE-2026-42666HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
- CVE-2026-42669HIGHCVSS 7.5EG 7.52026-06-02
Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventPrime: from n/a through 4.3.2.0.
- CVE-2026-42670HIGHCVSS 7.5EG 7.52026-06-02
Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/…
- CVE-2026-42671MEDIUMCVSS 6.5EG 6.52026-06-01
Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.
- CVE-2026-42675HIGHCVSS 7.3EG 7.32026-06-01
Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41.
- CVE-2026-42677HIGHCVSS 7.5EG 7.52026-06-01
Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.
- CVE-2026-42682CRITICALCVSS 9.1EG 9.12026-06-01
Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.
- CVE-2026-42726MEDIUMCVSS 6.5EG 6.52026-05-27
Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4…
- CVE-2026-42753HIGHCVSS 7.3EG 7.32026-05-27
Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10.
- CVE-2026-42763MEDIUMCVSS 6.5EG 6.52026-05-25
Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue affects SePay Gateway: from n/a through 1.1.20.
- CVE-2026-4277CRITICALCVSS 9.8EG 9.82026-04-07
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Dja…
- CVE-2026-42776MEDIUMCVSS 6.3EG 6.32026-05-25
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7.
- CVE-2026-42809CRITICALCVSS 9.9EG 9.92026-05-04
Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of a…
- CVE-2026-4281MEDIUMCVSS 5.3EG 5.32026-03-26
The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. This is due to missing capability checks on the connect() and listen_for_tokens() methods of …
- CVE-2026-4283CRITICALCVSS 9.1EG 9.12026-03-24
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unau…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →