CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,687 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 171 of 174
- CVE-2026-61440MEDIUMCVSS 6.5EG 6.52026-07-15
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member p…
- CVE-2026-61441MEDIUMCVSS 6.5EG 6.52026-07-10
PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-select…
- CVE-2026-61442HIGHCVSS 7.1EG 7.12026-07-11
PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created rec…
- CVE-2026-6145MEDIUMCVSS 5.3EG 5.32026-05-14
The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=crea…
- CVE-2026-61718MEDIUMCVSS 5.4EG 5.42026-07-16
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ URL prefix, so routes in src/ui/app/routes/cache…
- CVE-2026-61943HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
- CVE-2026-61952MEDIUMCVSS 4.9EG 4.92026-07-13
Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Pro…
- CVE-2026-61954HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
- CVE-2026-61958MEDIUMCVSS 5.4EG 5.42026-07-13
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: f…
- CVE-2026-61968MEDIUMCVSS 5.4EG 5.42026-07-13
Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 3.1.2.
- CVE-2026-61972MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
- CVE-2026-61973MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
- CVE-2026-61983MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.
- CVE-2026-61985MEDIUMCVSS 5.3EG 5.32026-07-13
Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.
- CVE-2026-6214MEDIUMCVSS 6.5EG 6.52026-05-07
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php failing to perform a capab…
- CVE-2026-62186HIGHCVSS 7.6EG 7.62026-07-13
OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit mis…
- CVE-2026-62191HIGHCVSS 7.1EG 7.12026-07-13
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconf…
- CVE-2026-62194HIGHCVSS 8.8EG 8.82026-07-13
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit mi…
- CVE-2026-62205HIGHCVSS 7.1EG 7.12026-07-17
OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path c…
- CVE-2026-62206HIGHCVSS 7.1EG 7.12026-07-17
OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform moderation actions that should have required a…
- CVE-2026-62207HIGHCVSS 8.8EG 8.82026-07-17
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy …
- CVE-2026-62218HIGHCVSS 8.8EG 8.82026-07-17
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authori…
- CVE-2026-6222MEDIUMCVSS 5.3EG 5.32026-05-07
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page` (admin/abstracts/class-admin-modul…
- CVE-2026-62232HIGHCVSS 7.4EG 7.42026-07-17
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know …
- CVE-2026-62233HIGHCVSS 8.8EG 8.82026-07-17
grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-ad…
- CVE-2026-62235MEDIUMCVSS 6.3EG 6.32026-07-17
Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less dir…
- CVE-2026-62328HIGHCVSS 7.5EG 7.52026-07-13
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API endpoints. Attackers can enumerate paginated r…
- CVE-2026-62348MEDIUMCVSS 5.4EG 5.42026-07-15
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run KILL SSMIGRATE <id> against an active shared-storage migration becau…
- CVE-2026-6235CRITICALCVSS 9.8EG 9.82026-04-22
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is…
- CVE-2026-63082MEDIUMCVSS 5.4EG 5.42026-07-16
Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets b…
- CVE-2026-63092MEDIUMCVSS 4.3EG 4.32026-07-21
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the mod…
- CVE-2026-63100MEDIUMCVSS 6.5EG 6.52026-07-17
Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show and update actions in the Settings::Ho…
- CVE-2026-63141MEDIUMCVSS 6.3EG 6.32026-07-21
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product e…
- CVE-2026-63143MEDIUMCVSS 4.3EG 4.32026-07-21
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the autho…
- CVE-2026-63262MEDIUMCVSS 4.3EG 4.32026-07-21
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.
- CVE-2026-6372HIGHCVSS 7.5EG 7.52026-04-15
Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept Cryptocurrencies with Plisio: from n/a through 2.0.5.
- CVE-2026-63741MEDIUMCVSS 6.5EG 6.52026-07-20
SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create arbitrary namespaces and databases by issuing USE commands,…
- CVE-2026-63758MEDIUMCVSS 5.4EG 5.42026-07-20
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. Attackers can issue KILL statements with targ…
- CVE-2026-6393MEDIUMCVSS 4.3EG 4.32026-04-24
The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce…
- CVE-2026-6441MEDIUMCVSS 4.3EG 4.32026-04-17
The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any capability check or nonce verification in the updateOptions() function, which is exposed via two…
- CVE-2026-64622HIGHCVSS 7.5EG 7.52026-07-20
Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read routes, so even when an operator configures a secret, unauthenticated actors can …
- CVE-2026-6472MEDIUMCVSS 5.4EG 5.42026-05-14
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL fun…
- CVE-2026-64814HIGHCVSS 8.6EG 8.62026-07-23
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
- CVE-2026-65007CRITICALCVSS 9.6EG 9.62026-07-21
The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the c…
- CVE-2026-65011MEDIUMCVSS 4.3EG 4.32026-07-22
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-pr…
- CVE-2026-65050MEDIUMCVSS 6.5EG 6.52026-07-21
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privil…
- CVE-2026-65055MEDIUMCVSS 5.3EG 5.32026-07-21
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data A…
- CVE-2026-6506HIGHCVSS 8.8EG 8.82026-05-14
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lackin…
- CVE-2026-6509HIGHCVSS 7.8EG 7.82026-07-05
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from <=0.6.3 before 0.6.6.
- CVE-2026-6510CRITICALCVSS 9.8EG 9.82026-05-14
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() …
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →