CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,687 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 172 of 174
- CVE-2026-6512CRITICALCVSS 9.1EG 9.12026-05-14
The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possi…
- CVE-2026-65452MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
- CVE-2026-65453MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
- CVE-2026-65457MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
- CVE-2026-65468MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
- CVE-2026-65469MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
- CVE-2026-65472MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
- CVE-2026-65476MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
- CVE-2026-65478MEDIUMCVSS 5.4EG 5.42026-07-23
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
- CVE-2026-65479MEDIUMCVSS 5.4EG 5.42026-07-23
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
- CVE-2026-65484MEDIUMCVSS 6.3EG 6.32026-07-23
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
- CVE-2026-65485MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
- CVE-2026-65486MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
- CVE-2026-65487MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
- CVE-2026-65489MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
- CVE-2026-65491MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
- CVE-2026-65495HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
- CVE-2026-65499MEDIUMCVSS 6.5EG 6.52026-07-23
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
- CVE-2026-65500HIGHCVSS 7.5EG 7.52026-07-23
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
- CVE-2026-65506MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
- CVE-2026-65524MEDIUMCVSS 4.3EG 4.32026-07-23
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
- CVE-2026-65525MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
- CVE-2026-65529MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
- CVE-2026-65530MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
- CVE-2026-65531MEDIUMCVSS 4.8EG 4.82026-07-23
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
- CVE-2026-65537MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
- CVE-2026-6589MEDIUMCVSS 4.3EG 4.32026-04-20
A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. …
- CVE-2026-65895HIGHCVSS 8.5EG 8.52026-07-23
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can di…
- CVE-2026-65916HIGHCVSS 8.1EG 8.12026-07-23
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send c…
- CVE-2026-6663MEDIUMCVSS 4.8EG 4.82026-05-12
The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints (gwd-backup.php and gwd-logs.php) not v…
- CVE-2026-6667MEDIUMCVSS 4.3EG 4.32026-05-09
PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have b…
- CVE-2026-6689MEDIUMCVSS 4.3EG 4.32026-06-12
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation (the check was only applied on update…
- CVE-2026-6703MEDIUMCVSS 4.3EG 4.32026-04-21
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized …
- CVE-2026-6706MEDIUMCVSS 6.5EG 6.52026-04-28
Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.…
- CVE-2026-6708MEDIUMCVSS 5.3EG 5.32026-05-12
The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability check on a REST API endpoint registered wit…
- CVE-2026-6709MEDIUMCVSS 4.3EG 4.32026-05-12
The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.1.2. This is due to a missing capability check and missing nonce verification in the save_settings() fun…
- CVE-2026-6792MEDIUMCVSS 6.5EG 6.52026-07-21
Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026.
- CVE-2026-6798MEDIUMCVSS 5.3EG 5.32026-06-19
The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an…
- CVE-2026-6803MEDIUMCVSS 5.3EG 5.32026-07-11
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions register…
- CVE-2026-6804MEDIUMCVSS 5.3EG 5.32026-07-11
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an …
- CVE-2026-6834MEDIUMCVSS 6.5EG 6.52026-04-22
The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method.
- CVE-2026-6883LOWCVSS 2.6EG 2.62026-05-14
GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to i…
- CVE-2026-6937MEDIUMCVSS 5.3EG 5.32026-05-28
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a use…
- CVE-2026-6963HIGHCVSS 8.8EG 8.82026-05-02
The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. This makes it possible for authenticated…
- CVE-2026-6964MEDIUMCVSS 5.3EG 5.32026-06-16
The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This …
- CVE-2026-7050MEDIUMCVSS 4.3EG 4.32026-05-12
The Forms Rb plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible fo…
- CVE-2026-7051MEDIUMCVSS 5.4EG 5.42026-05-13
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 8.9.0. This is due to a missing ownership verification in the B2S_Post_Tools::deleteUserP…
- CVE-2026-7108MEDIUMCVSS 4.3EG 4.32026-04-27
A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has be…
- CVE-2026-7249MEDIUMCVSS 4.3EG 4.32026-05-22
The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()` functions in all versions up to, and in…
- CVE-2026-7328MEDIUMCVSS 6.8EG 6.82026-07-22
Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands cont…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →