CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,632 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 166 of 173
- CVE-2026-53439MEDIUMCVSS 4.3EG 4.32026-06-10
Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".
- CVE-2026-53444HIGHCVSS 7.6EG 7.62026-07-15
Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/org.js, and server/models/team.js are globally callable without the admin authorization ch…
- CVE-2026-53445HIGHCVSS 7.1EG 7.12026-07-15
Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board by caller-supplied board ID without checking this.userId, membership, or admin access. Any …
- CVE-2026-53447MEDIUMCVSS 6.5EG 6.52026-07-15
Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or chec…
- CVE-2026-5347MEDIUMCVSS 5.3EG 5.32026-04-24
The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of capability checks and nonce verification in the admin_init hook that handles the permalin…
- CVE-2026-53514HIGHCVSS 7.7EG 7.72026-07-07
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabl…
- CVE-2026-5356HIGHCVSS 7.5EG 7.52026-07-08
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. This is due to the plugin's Stripe Connect payment processor…
- CVE-2026-53633CRITICALCVSS 9.8EG 9.82026-06-15
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, all…
- CVE-2026-53634MEDIUMCVSS 4.3EG 4.32026-06-10
Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enforce any authorization check. An authentic…
- CVE-2026-53640LOWCVSS 2.3EG 2.32026-07-06
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. While sibling write endpoints corre…
- CVE-2026-53643HIGHCVSS 8.7EG 8.72026-07-06
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API endpoints. The root cause is a combination of the `can_alway…
- CVE-2026-53647MEDIUMCVSS 6.9EG 6.92026-07-06
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without authentication. Any caller with a valid API key can retrieve al…
- CVE-2026-5371HIGHCVSS 7.1EG 7.12026-05-12
The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() …
- CVE-2026-53730HIGHCVSS 8.7EG 8.72026-07-07
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation annotation, allowing any authenticated user to specify datas…
- CVE-2026-53815MEDIUMCVSS 6.5EG 6.52026-06-11
OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient v…
- CVE-2026-53816HIGHCVSS 7.2EG 7.22026-06-11
OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node …
- CVE-2026-53818MEDIUMCVSS 6.6EG 6.62026-06-11
OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior throug…
- CVE-2026-53820MEDIUMCVSS 6.6EG 6.62026-06-12
OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated callers to bypass intended command restrictions. Attackers can reach the affected bundled MCP …
- CVE-2026-53821HIGHCVSS 8.8EG 8.82026-06-12
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can obtain cached operat…
- CVE-2026-53844MEDIUMCVSS 6.5EG 6.52026-06-16
OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guard…
- CVE-2026-53850MEDIUMCVSS 5.5EG 5.52026-06-16
OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command …
- CVE-2026-53851MEDIUMCVSS 5.3EG 5.32026-06-16
OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended agent processing by sending reactio…
- CVE-2026-53866HIGHCVSS 8.1EG 8.12026-06-16
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through…
- CVE-2026-5387CRITICALCVSS 9.3EG 9.32026-04-15
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modi…
- CVE-2026-54004MEDIUMCVSS 6.3EG 6.32026-06-18
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media …
- CVE-2026-54005HIGHCVSS 7.1EG 7.12026-06-18
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know or guess page IDs or UUIDs to retrieve page information, in…
- CVE-2026-54010HIGHCVSS 8.3EG 8.32026-06-17
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own chat message without checking whether the…
- CVE-2026-54012HIGHCVSS 7.1EG 7.12026-06-17
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can create, update, or import workspace models store arbitrary meta.knowledge entries on their mo…
- CVE-2026-54019MEDIUMCVSS 6.5EG 6.52026-06-17
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-level ACL checks, but the patch can still be bypassed when Milvus multitenancy mode is enabled. …
- CVE-2026-54027MEDIUMCVSS 6.5EG 6.52026-06-25
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool_resources (e.g., context, execute_code)…
- CVE-2026-54029MEDIUMCVSS 6.5EG 6.52026-06-25
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messages. The validateMes…
- CVE-2026-54052CRITICALCVSS 9.9EG 9.92026-07-14
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version …
- CVE-2026-54190MEDIUMCVSS 6.5EG 6.52026-06-16
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
- CVE-2026-5427MEDIUMCVSS 5.3EG 5.32026-04-17
The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability checks in the kubio_rest_pre_insert_import_assets() function, which is hooked to the rest_p…
- CVE-2026-54322HIGHCVSS 7.7EG 7.72026-06-16
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization role update and delete endpoints authorized the caller as an owner of the organization nam…
- CVE-2026-54329HIGHCVSS 7.7EG 7.72026-06-23
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in …
- CVE-2026-54415HIGHCVSS 8.1EG 8.12026-06-17
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over n…
- CVE-2026-54475HIGHCVSS 7.5EG 7.52026-06-30
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be brok…
- CVE-2026-54568MEDIUMCVSS 4.3EG 4.32026-07-16
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id …
- CVE-2026-54628HIGHCVSS 8.6EG 8.62026-07-14
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode ## Summary Anyquery's `server` mode does not restrict outbound HTTP requests initiated by its built-in SQLite virtual table modules …
- CVE-2026-54629HIGHCVSS 7.5EG 7.52026-07-14
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode ## Summary Anyquery's `server` mode lacks input sanitization and access control over its built-in SQLite virtual table modules (e.g., `csv_reader…
- CVE-2026-5464HIGHCVSS 7.2EG 7.22026-04-23
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due t…
- CVE-2026-54695MEDIUMCVSS 6.5EG 6.52026-06-18
Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections …
- CVE-2026-54802HIGHCVSS 7.5EG 7.52026-06-17
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
- CVE-2026-54810HIGHCVSS 7.5EG 7.52026-06-17
Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexi XPay: from n/a through 8.3.1.
- CVE-2026-54828HIGHCVSS 7.5EG 7.52026-06-25
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
- CVE-2026-54830HIGHCVSS 7.5EG 7.52026-06-25
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
- CVE-2026-54832HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
- CVE-2026-54835HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
- CVE-2026-54837HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →