CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,632 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 168 of 173
- CVE-2026-56773HIGHCVSS 8.8EG 8.82026-06-26
Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and t…
- CVE-2026-5693MEDIUMCVSS 5.3EG 5.32026-05-12
The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and in…
- CVE-2026-57205MEDIUMCVSS 4.3EG 4.32026-07-16
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoint…
- CVE-2026-57206HIGHCVSS 8.6EG 8.62026-07-16
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, includi…
- CVE-2026-57221MEDIUMCVSS 5.0EG 5.02026-07-10
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user …
- CVE-2026-57285MEDIUMCVSS 4.3EG 4.32026-06-24
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configurati…
- CVE-2026-57286MEDIUMCVSS 4.3EG 4.32026-06-24
A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revisio…
- CVE-2026-57291MEDIUMCVSS 5.4EG 5.42026-06-24
Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another meth…
- CVE-2026-57293MEDIUMCVSS 4.3EG 4.32026-06-24
An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of …
- CVE-2026-57294MEDIUMCVSS 5.4EG 5.42026-06-24
A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through ano…
- CVE-2026-57297MEDIUMCVSS 4.3EG 4.32026-06-24
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and…
- CVE-2026-57299MEDIUMCVSS 4.3EG 4.32026-06-24
Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.
- CVE-2026-57300MEDIUMCVSS 4.3EG 4.32026-06-24
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.
- CVE-2026-57304MEDIUMCVSS 5.4EG 5.42026-06-24
A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username and password.
- CVE-2026-57307MEDIUMCVSS 4.2EG 4.22026-06-24
A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through …
- CVE-2026-57323MEDIUMCVSS 5.8EG 5.82026-06-26
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
- CVE-2026-57324MEDIUMCVSS 6.5EG 6.52026-06-26
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
- CVE-2026-57327MEDIUMCVSS 6.3EG 6.32026-06-29
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
- CVE-2026-57332HIGHCVSS 7.1EG 7.12026-06-29
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
- CVE-2026-57334MEDIUMCVSS 6.5EG 6.52026-06-29
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
- CVE-2026-57335MEDIUMCVSS 6.5EG 6.52026-06-29
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
- CVE-2026-57339MEDIUMCVSS 6.5EG 6.52026-06-29
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
- CVE-2026-57340MEDIUMCVSS 6.5EG 6.52026-06-29
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
- CVE-2026-57353MEDIUMCVSS 6.5EG 6.52026-07-02
Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.
- CVE-2026-57355MEDIUMCVSS 6.5EG 6.52026-07-02
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
- CVE-2026-57375MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4.
- CVE-2026-57377MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowAddons: from n/a through <= 1.6.8.
- CVE-2026-57378HIGHCVSS 7.5EG 7.52026-07-13
Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.
- CVE-2026-57390MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Prod…
- CVE-2026-57392MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
- CVE-2026-57395MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
- CVE-2026-57400MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager f…
- CVE-2026-57404MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manag…
- CVE-2026-57405HIGHCVSS 7.1EG 7.12026-07-13
Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1.
- CVE-2026-57406MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6.
- CVE-2026-57408MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 4.…
- CVE-2026-57412MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Codemenschen Gift Vouchers gift-voucher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gift Vouchers: from n/a through <= 4.6.9.
- CVE-2026-57418MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a th…
- CVE-2026-57419MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce…
- CVE-2026-57424MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n…
- CVE-2026-57429MEDIUMCVSS 6.5EG 6.52026-06-25
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions. Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
- CVE-2026-57430MEDIUMCVSS 4.3EG 4.32026-06-26
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
- CVE-2026-57494HIGHCVSS 7.1EG 7.12026-06-18
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target a…
- CVE-2026-57498CRITICALCVSS 9.6EG 9.62026-06-29
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any oper…
- CVE-2026-57518HIGHCVSS 8.8EG 8.82026-06-26
Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization…
- CVE-2026-57520HIGHCVSS 7.1EG 7.12026-06-25
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in…
- CVE-2026-57521MEDIUMCVSS 4.3EG 4.32026-06-25
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpo…
- CVE-2026-5753MEDIUMCVSS 6.5EG 6.52026-05-06
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_sched…
- CVE-2026-57619MEDIUMCVSS 6.5EG 6.52026-06-25
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
- CVE-2026-57622MEDIUMCVSS 4.3EG 4.32026-06-26
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →