CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,632 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 164 of 173
- CVE-2026-47721MEDIUMCVSS 6.3EG 6.32026-06-08
FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions ## Summary An authorization issue in the Scheduler API allowed authenticated non-admin users to create or modify scheduled actions…
- CVE-2026-47728MEDIUMCVSS 4.3EG 4.32026-05-26
Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An authenticated user with access to one pro…
- CVE-2026-47740HIGHCVSS 8.1EG 8.12026-05-29
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orde…
- CVE-2026-47742MEDIUMCVSS 6.5EG 6.52026-05-29
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regar…
- CVE-2026-47745MEDIUMCVSS 6.5EG 6.52026-05-29
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete) that were rendered for any authenticat…
- CVE-2026-4795MEDIUMCVSS 6.5EG 6.52026-05-26
A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versio…
- CVE-2026-48008MEDIUMCVSS 6.5EG 6.52026-06-04
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /ap…
- CVE-2026-48014MEDIUMCVSS 6.5EG 6.52026-06-04
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in src/Core/Checkout/Order/A…
- CVE-2026-4807MEDIUMCVSS 6.5EG 6.52026-05-07
The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the pu…
- CVE-2026-48119HIGHCVSS 7.1EG 7.12026-06-01
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results for other users' services. This issue has …
- CVE-2026-4812MEDIUMCVSS 5.3EG 5.32026-04-15
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter …
- CVE-2026-48127MEDIUMCVSS 5.3EG 5.32026-07-10
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.2…
- CVE-2026-48151HIGHCVSS 7.5EG 7.52026-05-27
Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema…
- CVE-2026-4843MEDIUMCVSS 4.3EG 4.32026-05-21
The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possible…
- CVE-2026-48492MEDIUMCVSS 6.5EG 6.52026-06-23
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a …
- CVE-2026-48500MEDIUMCVSS 6.5EG 6.52026-06-22
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the…
- CVE-2026-48582CRITICALCVSS 9.6EG 9.62026-06-19
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
- CVE-2026-48592MEDIUMCVSS 5.3EG 5.32026-05-26
Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthorized job worker substitution. The handle_event("save-job", ...) handler in 'Elixir.Oban.Web.Jobs.DetailComponent' does…
- CVE-2026-48709LOWCVSS 3.7EG 3.72026-06-15
OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.go does not perform any authentication or authorization checks. Unli…
- CVE-2026-48783MEDIUMCVSS 4.8EG 4.82026-06-17
Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's clai…
- CVE-2026-48797CRITICALCVSS 9.3EG 9.32026-06-17
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training …
- CVE-2026-4881MEDIUMCVSS 6.5EG 6.52026-06-04
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.
- CVE-2026-48811MEDIUMCVSS 4.3EG 4.32026-05-29
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete an internal note (private thread) from any conversation, even after that user's ac…
- CVE-2026-48835HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
- CVE-2026-48873HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.
- CVE-2026-4888MEDIUMCVSS 4.3EG 4.32026-05-27
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to…
- CVE-2026-48881CRITICALCVSS 9.1EG 9.12026-06-15
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
- CVE-2026-48883HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
- CVE-2026-48887MEDIUMCVSS 6.5EG 6.52026-06-15
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
- CVE-2026-48941MEDIUMCVSS 6.5EG 6.52026-06-25
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/`
- CVE-2026-48969MEDIUMCVSS 6.5EG 6.52026-06-15
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
- CVE-2026-48971MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for WooCommerce: from n/a through 2.5…
- CVE-2026-48973MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14.
- CVE-2026-49045MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11.
- CVE-2026-49047MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27.
- CVE-2026-49051MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6.
- CVE-2026-49052MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
- CVE-2026-49053MEDIUMCVSS 5.3EG 5.32026-05-27
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
- CVE-2026-49054MEDIUMCVSS 4.3EG 4.32026-05-27
Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly... Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Leve…
- CVE-2026-49057HIGHCVSS 7.5EG 7.52026-06-17
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
- CVE-2026-49065HIGHCVSS 8.2EG 8.22026-06-15
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
- CVE-2026-49070HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
- CVE-2026-49072MEDIUMCVSS 6.5EG 6.52026-06-17
Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
- CVE-2026-49081HIGHCVSS 8.2EG 8.22026-06-17
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
- CVE-2026-4916LOWCVSS 2.7EG 2.72026-04-08
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove high…
- CVE-2026-49205MEDIUMCVSS 6.5EG 6.52026-06-18
phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BA…
- CVE-2026-4925MEDIUMCVSS 5.0EG 5.02026-04-01
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. …
- CVE-2026-49258HIGHCVSS 8.8EG 8.82026-06-26
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) ## Summary The web UI (`/ui/*`) does not apply the per-operator CA scoping the JSON API received for GHSA-598g-h2vc-h5…
- CVE-2026-49274MEDIUMCVSS 5.3EG 5.32026-06-18
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission disabled allowed authenticated users to provide an inaccessible parent page or …
- CVE-2026-49288MEDIUMCVSS 4.3EG 4.32026-06-19
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, as…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →