CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,635 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 169 of 173
- CVE-2026-57619MEDIUMCVSS 6.5EG 6.52026-06-25
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
- CVE-2026-57622MEDIUMCVSS 4.3EG 4.32026-06-26
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
- CVE-2026-57632MEDIUMCVSS 5.4EG 5.42026-06-26
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
- CVE-2026-57640MEDIUMCVSS 4.3EG 4.32026-06-26
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
- CVE-2026-57645HIGHCVSS 8.1EG 8.12026-06-26
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
- CVE-2026-57648MEDIUMCVSS 4.3EG 4.32026-06-26
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
- CVE-2026-57649MEDIUMCVSS 4.3EG 4.32026-06-26
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
- CVE-2026-57654MEDIUMCVSS 6.5EG 6.52026-06-26
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
- CVE-2026-57660MEDIUMCVSS 5.3EG 5.32026-06-26
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
- CVE-2026-57661MEDIUMCVSS 5.4EG 5.42026-06-26
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
- CVE-2026-57669MEDIUMCVSS 6.5EG 6.52026-07-02
Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.
- CVE-2026-57685MEDIUMCVSS 4.3EG 4.32026-07-02
Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
- CVE-2026-57688HIGHCVSS 8.2EG 8.22026-07-02
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
- CVE-2026-57689MEDIUMCVSS 4.3EG 4.32026-07-02
Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
- CVE-2026-57705HIGHCVSS 7.5EG 7.52026-07-13
Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.
- CVE-2026-57720MEDIUMCVSS 4.3EG 4.32026-07-01
Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.
- CVE-2026-57721MEDIUMCVSS 5.3EG 5.32026-07-01
Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6.
- CVE-2026-57727HIGHCVSS 7.5EG 7.52026-07-13
Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.
- CVE-2026-57729HIGHCVSS 7.5EG 7.52026-07-13
Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.
- CVE-2026-57730MEDIUMCVSS 4.3EG 4.32026-07-02
Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
- CVE-2026-57731MEDIUMCVSS 6.5EG 6.52026-07-02
Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
- CVE-2026-57740HIGHCVSS 7.1EG 7.12026-07-13
Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through…
- CVE-2026-57746HIGHCVSS 7.1EG 7.12026-07-02
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
- CVE-2026-57750MEDIUMCVSS 5.3EG 5.32026-07-02
Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
- CVE-2026-57760MEDIUMCVSS 5.3EG 5.32026-07-02
Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.
- CVE-2026-57774MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0.
- CVE-2026-57776MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7.
- CVE-2026-57778MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking …
- CVE-2026-57779MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.
- CVE-2026-57781MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MeetingHub: from n/a through <= 1.25.10.
- CVE-2026-57782MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.
- CVE-2026-57797MEDIUMCVSS 4.3EG 4.32026-07-13
Missing Authorization vulnerability in ThemeMove EduMall edumall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EduMall: from n/a through <= 4.5.1.
- CVE-2026-57812MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a thr…
- CVE-2026-57830HIGHCVSS 8.8EG 9.12026-07-13
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
- CVE-2026-57850HIGHCVSS 8.3EG 8.32026-07-10
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options re…
- CVE-2026-57921HIGHCVSS 7.5EG 7.52026-06-26
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
- CVE-2026-57922MEDIUMCVSS 5.3EG 5.32026-06-26
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
- CVE-2026-57923HIGHCVSS 7.5EG 7.52026-06-26
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
- CVE-2026-57925MEDIUMCVSS 5.3EG 5.32026-06-26
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
- CVE-2026-57946LOWCVSS 3.7EG 3.72026-06-29
Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers …
- CVE-2026-57949MEDIUMCVSS 6.5EG 6.52026-06-29
ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by ite…
- CVE-2026-57952MEDIUMCVSS 6.5EG 6.52026-06-29
Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verif…
- CVE-2026-57954MEDIUMCVSS 4.3EG 4.32026-06-29
Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row …
- CVE-2026-58165HIGHCVSS 8.8EG 8.82026-06-30
OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, inclu…
- CVE-2026-58167MEDIUMCVSS 6.5EG 6.52026-06-30
Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) u…
- CVE-2026-58168HIGHCVSS 8.8EG 8.82026-06-30
DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools …
- CVE-2026-58176MEDIUMCVSS 6.5EG 6.52026-06-30
RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the controller declares no class-level or method-level authorization a…
- CVE-2026-58279MEDIUMCVSS 6.5EG 6.52026-07-14
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
- CVE-2026-58373MEDIUMCVSS 4.3EG 4.32026-06-30
CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing c…
- CVE-2026-58377HIGHCVSS 8.1EG 8.12026-06-30
JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController …
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →