CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,632 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 167 of 173
- CVE-2026-54840HIGHCVSS 7.3EG 7.32026-06-26
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
- CVE-2026-54842HIGHCVSS 8.1EG 8.12026-06-25
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly... Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This …
- CVE-2026-54844HIGHCVSS 7.5EG 7.52026-06-25
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
- CVE-2026-54846HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions.
- CVE-2026-54847HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
- CVE-2026-5488MEDIUMCVSS 5.3EG 5.32026-04-24
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and res…
- CVE-2026-5502MEDIUMCVSS 5.3EG 5.32026-04-17
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing authorization check in the tutor_update_c…
- CVE-2026-55052HIGHCVSS 8.8EG 8.82026-07-14
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-55188HIGHCVSS 8.2EG 8.22026-06-26
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replica…
- CVE-2026-55189HIGHCVSS 7.7EG 7.72026-06-26
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM aut…
- CVE-2026-55417MEDIUMCVSS 6.9EG 6.92026-07-07
Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile option, visiting their profile HTML route (`/username`) correctly returns 404. However, the `/…
- CVE-2026-55432MEDIUMCVSS 5.4EG 5.42026-07-06
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `Ma…
- CVE-2026-55433MEDIUMCVSS 5.4EG 5.42026-07-06
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on th…
- CVE-2026-55440MEDIUMCVSS 6.5EG 6.52026-07-16
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py wit…
- CVE-2026-55476MEDIUMCVSS 4.3EG 4.32026-07-10
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an a…
- CVE-2026-55518CRITICALCVSS 9.6EG 9.62026-06-17
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new path, but the actua…
- CVE-2026-55542MEDIUMCVSS 4.3EG 4.32026-06-23
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obta…
- CVE-2026-55544HIGHCVSS 7.6EG 7.62026-07-20
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The applicat…
- CVE-2026-55548MEDIUMCVSS 4.3EG 4.32026-07-16
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omit…
- CVE-2026-55550HIGHCVSS 7.1EG 7.12026-07-20
NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, and deletion to `manager` and `ad…
- CVE-2026-55628MEDIUMCVSS 5.5EG 5.52026-07-01
In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.
- CVE-2026-55638HIGHCVSS 8.6EG 8.62026-07-10
9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. A remote unauthenticate…
- CVE-2026-5572MEDIUMCVSS 4.3EG 4.32026-04-05
A security flaw has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has b…
- CVE-2026-5574MEDIUMCVSS 6.5EG 6.52026-04-05
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to missing authorization. The a…
- CVE-2026-55762HIGHCVSS 8.1EG 8.12026-06-24
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerprint REST endpoint enforces authentication (authRequired: true) but …
- CVE-2026-55838MEDIUMCVSS 4.3EG 4.32026-06-26
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin…
- CVE-2026-56023MEDIUMCVSS 5.4EG 5.42026-06-25
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
- CVE-2026-56025HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
- CVE-2026-56038HIGHCVSS 8.8EG 8.82026-06-26
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
- CVE-2026-56061HIGHCVSS 7.5EG 7.52026-06-26
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
- CVE-2026-56063HIGHCVSS 8.3EG 8.32026-06-26
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
- CVE-2026-56104HIGHCVSS 8.2EG 7.42026-06-22
Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownersh…
- CVE-2026-56115HIGHCVSS 8.8EG 5.32026-06-23
Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/a…
- CVE-2026-56213MEDIUMCVSS 5.3EG 5.32026-06-20
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgREST RPC, allowing unauthenticated attackers to insert arbitrary rows into version_meta for a…
- CVE-2026-5624MEDIUMCVSS 4.3EG 4.32026-04-06
A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit ha…
- CVE-2026-56250HIGHCVSS 7.5EG 7.52026-07-08
Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbitrary R2 bundle objects. Attackers can patch r2_path to point to victim objects, soft-delet…
- CVE-2026-56279HIGHCVSS 7.5EG 7.52026-07-10
Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated attackers can supply arbitrary user UU…
- CVE-2026-56280HIGHCVSS 7.1EG 7.12026-06-22
Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running native builds. The endpoint registers an abort listener on the SSE stream that unconditio…
- CVE-2026-56341HIGHCVSS 7.5EG 7.52026-06-20
AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attacke…
- CVE-2026-56384MEDIUMCVSS 4.3EG 4.32026-06-21
Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive pre…
- CVE-2026-56396HIGHCVSS 8.8EG 8.82026-06-21
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_s…
- CVE-2026-56402MEDIUMCVSS 6.5EG 6.52026-06-23
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like…
- CVE-2026-56423HIGHCVSS 8.8EG 8.82026-06-22
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authoriz…
- CVE-2026-56424HIGHCVSS 8.8EG 8.82026-06-22
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged auth…
- CVE-2026-56668HIGHCVSS 8.1EG 8.12026-07-10
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client o…
- CVE-2026-56695MEDIUMCVSS 6.5EG 6.52026-06-23
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots …
- CVE-2026-56696MEDIUMCVSS 5.4EG 5.42026-06-23
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious con…
- CVE-2026-56742HIGHCVSS 8.9EG 8.92026-07-15
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Ser…
- CVE-2026-56767HIGHCVSS 8.8EG 8.82026-06-25
Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Goo…
- CVE-2026-56768HIGHCVSS 8.8EG 8.82026-06-25
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →