CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,686 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 170 of 174
- CVE-2026-57830CRITICALCVSS 9.1EG 9.12026-07-13
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
- CVE-2026-57850HIGHCVSS 8.3EG 8.32026-07-10
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options re…
- CVE-2026-57921HIGHCVSS 7.5EG 7.52026-06-26
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
- CVE-2026-57922MEDIUMCVSS 5.3EG 5.32026-06-26
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
- CVE-2026-57923HIGHCVSS 7.5EG 7.52026-06-26
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
- CVE-2026-57925MEDIUMCVSS 5.3EG 5.32026-06-26
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
- CVE-2026-57946LOWCVSS 3.7EG 3.72026-06-29
Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers …
- CVE-2026-57949MEDIUMCVSS 6.5EG 6.52026-06-29
ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by ite…
- CVE-2026-57952MEDIUMCVSS 6.5EG 6.52026-06-29
Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verif…
- CVE-2026-57954MEDIUMCVSS 4.3EG 4.32026-06-29
Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row …
- CVE-2026-58165HIGHCVSS 8.8EG 8.82026-06-30
OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, inclu…
- CVE-2026-58167MEDIUMCVSS 6.5EG 6.52026-06-30
Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) u…
- CVE-2026-58168HIGHCVSS 8.8EG 8.82026-06-30
DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools …
- CVE-2026-58176MEDIUMCVSS 6.5EG 6.52026-06-30
RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the controller declares no class-level or method-level authorization a…
- CVE-2026-58279MEDIUMCVSS 6.5EG 6.52026-07-14
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
- CVE-2026-58373MEDIUMCVSS 4.3EG 4.32026-06-30
CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing c…
- CVE-2026-58377HIGHCVSS 8.1EG 8.12026-06-30
JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController …
- CVE-2026-58408MEDIUMCVSS 6.5EG 6.52026-07-13
ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admin/export UI and exfiltrate the entire member directory. The POST /CSVCreateFile.php endpoint generates and streams a CS…
- CVE-2026-58410HIGHCVSS 7.1EG 7.12026-07-13
ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify other families’ records. An authenticated …
- CVE-2026-58448MEDIUMCVSS 6.5EG 6.52026-06-30
yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an …
- CVE-2026-58473CRITICALCVSS 9.1EG 9.12026-07-07
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs…
- CVE-2026-58482MEDIUMCVSS 5.9EG 5.92026-07-20
Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which `ApprovalGate`…
- CVE-2026-58589MEDIUMCVSS 5.4EG 5.42026-07-10
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
- CVE-2026-58590MEDIUMCVSS 5.4EG 5.42026-07-10
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
- CVE-2026-59097MEDIUMCVSS 5.3EG 5.32026-07-02
Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue d…
- CVE-2026-59216CRITICALCVSS 9.0EG 9.02026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the s…
- CVE-2026-59217MEDIUMCVSS 4.3EG 4.32026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded files to a target knowledge base without applying the write…
- CVE-2026-59225MEDIUMCVSS 6.3EG 6.32026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through tas…
- CVE-2026-59226MEDIUMCVSS 4.3EG 4.32026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automation…
- CVE-2026-59227MEDIUMCVSS 5.4EG 5.42026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required only a verified account and did not enforce the global image-edit switch or the per-user ima…
- CVE-2026-59255HIGHCVSS 7.1EG 7.12026-07-15
BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens c…
- CVE-2026-59262MEDIUMCVSS 6.5EG 6.52026-07-08
AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines. Attackers can supply arbitrary document GUIDs …
- CVE-2026-5944HIGHCVSS 8.2EG 8.22026-04-28
An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deploym…
- CVE-2026-59509CRITICALCVSS 9.2EG 9.22026-07-05
An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression…
- CVE-2026-59522MEDIUMCVSS 6.5EG 6.52026-07-23
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
- CVE-2026-59523MEDIUMCVSS 6.5EG 6.52026-07-13
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a thr…
- CVE-2026-59547HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
- CVE-2026-59677MEDIUMCVSS 6.8EG 6.82026-07-23
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils …
- CVE-2026-59704HIGHCVSS 7.1EG 7.12026-07-07
Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can supply arbitrary video IDs to read sensitive …
- CVE-2026-59708HIGHCVSS 7.5EG 7.52026-07-07
The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retriev…
- CVE-2026-59709MEDIUMCVSS 4.3EG 4.32026-07-07
Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attacke…
- CVE-2026-59796HIGHCVSS 8.1EG 8.12026-07-10
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
- CVE-2026-59805MEDIUMCVSS 6.5EG 6.52026-07-08
Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_access …
- CVE-2026-59853MEDIUMCVSS 6.5EG 6.52026-07-09
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage…
- CVE-2026-60118MEDIUMCVSS 5.3EG 5.32026-07-14
Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without aut…
- CVE-2026-60119MEDIUMCVSS 5.4EG 5.42026-07-14
Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding a malicious event title containing the <…
- CVE-2026-60124MEDIUMCVSS 5.3EG 5.32026-07-08
An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results…
- CVE-2026-6109MEDIUMCVSS 4.3EG 4.32026-04-12
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manip…
- CVE-2026-61267HIGHCVSS 7.3EG 7.32026-07-21
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated …
- CVE-2026-61440MEDIUMCVSS 6.5EG 6.52026-07-15
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member p…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →