CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,632 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 165 of 173
- CVE-2026-49291HIGHCVSS 8.1EG 8.12026-06-19
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that…
- CVE-2026-49292LOWCVSS 0.0EG 0.02026-07-02
Kiwi TCMS's /init-db/ page renders and responds to requests after first use Kiwi TCMS provides the /init-db/ page as part of its setup mechanism for administrators who prefer a browser instead of the command line. In previous versions of …
- CVE-2026-49357HIGHCVSS 8.8EG 8.82026-06-19
Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable H…
- CVE-2026-49367HIGHCVSS 8.8EG 8.02026-05-29
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
- CVE-2026-49374HIGHCVSS 7.6EG 7.62026-05-29
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
- CVE-2026-49378MEDIUMCVSS 4.3EG 4.32026-05-29
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
- CVE-2026-49385MEDIUMCVSS 6.5EG 6.52026-05-29
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
- CVE-2026-49394HIGHCVSS 7.1EG 7.12026-07-10
Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue…
- CVE-2026-4949MEDIUMCVSS 4.3EG 4.32026-04-15
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.16.12. This is …
- CVE-2026-49741HIGHCVSS 8.7EG 8.72026-06-09
Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persistence validation and permission checks. Thi…
- CVE-2026-4977MEDIUMCVSS 4.3EG 4.32026-04-10
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to insufficient field-level pe…
- CVE-2026-49775MEDIUMCVSS 6.5EG 6.52026-06-15
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
- CVE-2026-49782MEDIUMCVSS 5.4EG 5.42026-06-02
Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0.
- CVE-2026-49821HIGHCVSS 7.7EG 7.72026-06-10
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's buildermgr controller processed Package CRDs without verifying…
- CVE-2026-49822HIGHCVSS 7.7EG 7.72026-06-10
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a KubernetesWatchTrigger (KWT…
- CVE-2026-4986MEDIUMCVSS 5.3EG 5.32026-06-09
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbit…
- CVE-2026-49948HIGHCVSS 8.1EG 8.12026-06-09
Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only ver…
- CVE-2026-49956MEDIUMCVSS 6.5EG 6.52026-06-09
Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to other profiles by querying the session search endpoint without active-profile filtering. Att…
- CVE-2026-49991HIGHCVSS 8.6EG 8.62026-06-26
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write a…
- CVE-2026-50006CRITICALCVSS 9.1EG 9.12026-07-14
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode ## Summary Anyquery's `server` mode does not disable or restrict native SQLite disk manipulation commands…
- CVE-2026-50007HIGHCVSS 7.2EG 7.22026-07-07
Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budget file to perform owner-only file management actions. A non-owner shared user can call fi…
- CVE-2026-50026MEDIUMCVSS 6.9EG 6.92026-06-12
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.
- CVE-2026-50084MEDIUMCVSS 6.5EG 9.62026-06-12
The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:L…
- CVE-2026-50108HIGHCVSS 7.5EG 7.52026-06-12
The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can…
- CVE-2026-50137CRITICALCVSS 9.4EG 9.42026-06-22
Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can call this endpoint with no auth and obtain a 15-minute pre…
- CVE-2026-5022MEDIUMCVSS 5.3EG 5.32026-03-27
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file…
- CVE-2026-50244MEDIUMCVSS 5.3EG 5.32026-06-12
The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequentia…
- CVE-2026-5025MEDIUMCVSS 6.5EG 6.52026-03-27
The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.…
- CVE-2026-50282HIGHCVSS 0.0EG 0.02026-07-02
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves We have identified an authorization issue in Craft CMS where a forced folder move can delete a conflicting destination folder without destination del…
- CVE-2026-50283MEDIUMCVSS 5.3EG 5.32026-07-01
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in the AssetsController::actionReplaceFile that can delete a source asset without source delete…
- CVE-2026-50284HIGHCVSS 7.1EG 7.12026-07-01
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theAssetsController::actionDeleteFolder() only requires the deleteAssets:<volume-uid> permission for the target folder. It …
- CVE-2026-5139MEDIUMCVSS 5.4EG 5.42026-06-22
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler, which allows any a…
- CVE-2026-5146MEDIUMCVSS 4.3EG 4.32026-05-12
Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the fol…
- CVE-2026-5163MEDIUMCVSS 6.5EG 6.52026-05-18
Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of threads in private channels and direct messages they do not h…
- CVE-2026-5175MEDIUMCVSS 5.0EG 5.02026-04-01
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication…
- CVE-2026-5200HIGHCVSS 8.8EG 8.82026-05-20
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly v…
- CVE-2026-5228HIGHCVSS 8.8EG 8.82026-06-04
Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.
- CVE-2026-5230HIGHCVSS 7.1EG 7.12026-06-15
Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.262…
- CVE-2026-52701MEDIUMCVSS 6.5EG 6.52026-06-26
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
- CVE-2026-52711HIGHCVSS 7.5EG 7.52026-06-16
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
- CVE-2026-52714MEDIUMCVSS 5.9EG 5.92026-06-16
Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
- CVE-2026-52799HIGHCVSS 7.5EG 7.52026-06-22
Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository.…
- CVE-2026-52812HIGHCVSS 7.1EG 7.12026-06-23
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS-root>/<oid[0]>/<oid[1]>/<oid>) but per-repo authorization lives in the lfs_object table keyed (repo_id, oid). serveUpl…
- CVE-2026-52839LOWCVSS 3.3EG 3.32026-07-14
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. Howeve…
- CVE-2026-52866MEDIUMCVSS 6.5EG 6.52026-06-19
An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.
- CVE-2026-52870HIGHCVSS 7.6EG 7.62026-07-15
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and…
- CVE-2026-52892MEDIUMCVSS 6.5EG 6.52026-07-15
Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAccess for mutating cust…
- CVE-2026-5294CRITICALCVSS 9.8EG 9.82026-05-05
The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispatch and reaching a plugin installer help…
- CVE-2026-5296MEDIUMCVSS 4.3EG 4.32026-05-27
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level, could have allowed an authenticated use…
- CVE-2026-53438MEDIUMCVSS 4.3EG 4.32026-06-10
A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →