CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
10,777 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 3 of 216
- CVE-2013-3960CRITICALCVSS 9.9EG 9.92020-01-24
Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass
- CVE-2019-15954CRITICALCVSS 9.9EG 9.92019-09-05
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript c…
- CVE-2026-83941CRITICALCVSS 8.8EG 9.92026-09-08
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
- CVE-2026-12647CRITICALCVSS 8.8EG 9.92026-09-08
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- CVE-2026-12646CRITICALCVSS 8.8EG 9.92026-09-08
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- CVE-2026-12645CRITICALCVSS 8.8EG 9.92026-09-08
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- CVE-2026-84254CRITICALCVSS 9.8EG 9.82026-10-11
The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-o…
- CVE-2026-84253CRITICALCVSS 9.8EG 9.82026-10-11
The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on…
- CVE-2026-84252CRITICALCVSS 9.8EG 9.82026-10-11
The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to WP…
- CVE-2026-84251CRITICALCVSS 9.8EG 9.82026-10-11
The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on t…
- CVE-2026-106511CRITICALCVSS 9.8EG 9.82026-10-06
MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with…
- CVE-2026-105859CRITICALCVSS 9.8EG 9.82026-10-06
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents w…
- CVE-2026-104070CRITICALCVSS 9.8EG 9.82026-10-06
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, cau…
- CVE-2026-94541CRITICALCVSS 9.8EG 9.82026-10-02
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform a…
- CVE-2026-91048CRITICALCVSS 9.8EG 9.82026-09-29
The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one ho…
- CVE-2026-86591CRITICALCVSS 9.8EG 9.82026-09-19
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege esc…
- CVE-2026-61550CRITICALCVSS 9.8EG 9.82026-09-18
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to conn…
- CVE-2026-14349CRITICALCVSS 9.8EG 9.82026-09-16
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized …
- CVE-2026-73807CRITICALCVSS 9.8EG 9.82026-09-15
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management f…
- CVE-2026-75030CRITICALCVSS 9.8EG 9.82026-09-14
Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue a…
- CVE-2026-72709CRITICALCVSS 9.8EG 9.82026-09-11
SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-…
- CVE-2026-41871CRITICALCVSS 9.8EG 9.82026-09-09
Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are rec…
- CVE-2026-87534CRITICALCVSS 9.8EG 9.82026-09-09
Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: M…
- CVE-2026-82923CRITICALCVSS 9.8EG 9.82026-09-04
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL…
- CVE-2026-85433CRITICALCVSS 9.8EG 9.82026-09-03
MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd…
- CVE-2026-84238CRITICALCVSS 9.8EG 9.82026-09-03
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
- CVE-2026-54569CRITICALCVSS 9.8EG 9.82026-08-26
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authori…
- CVE-2026-18431CRITICALCVSS 9.8EG 9.82026-08-26
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authori…
- CVE-2026-72843CRITICALCVSS 9.8EG 9.82026-08-20
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller,…
- CVE-2026-73665CRITICALCVSS 9.8EG 9.82026-08-13
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated c…
- CVE-2026-49819CRITICALCVSS 9.8EG 9.82026-08-12
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuse…
- CVE-2026-14365CRITICALCVSS 9.8EG 9.82026-08-07
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized …
- CVE-2026-48085CRITICALCVSS 9.8EG 9.82026-08-06
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-ac…
- CVE-2026-28005CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
- CVE-2026-68979CRITICALCVSS 9.8EG 9.82026-08-03
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that aff…
- CVE-2026-16300CRITICALCVSS 9.8EG 9.82026-08-03
The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeove…
- CVE-2026-16184CRITICALCVSS 9.8EG 9.82026-07-28
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
- CVE-2026-64746CRITICALCVSS 9.8EG 9.82026-07-27
An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user …
- CVE-2026-15015CRITICALCVSS 9.8EG 9.82026-07-23
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an ac…
- CVE-2026-10768CRITICALCVSS 9.8EG 9.82026-07-10
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
- CVE-2026-14245CRITICALCVSS 9.8EG 9.82026-07-09
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_pa…
- CVE-2026-12153CRITICALCVSS 9.8EG 9.82026-07-08
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it pos…
- CVE-2026-31309CRITICALCVSS 9.8EG 9.82026-07-08
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a cra…
- CVE-2026-57139CRITICALCVSS 9.8EG 9.82026-06-18
PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication or…
- CVE-2026-57131CRITICALCVSS 9.8EG 9.82026-06-18
PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-c…
- CVE-2026-53633CRITICALCVSS 9.8EG 9.82026-06-15
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, all…
- CVE-2026-38329CRITICALCVSS 9.8EG 9.82026-06-15
Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker …
- CVE-2026-46614CRITICALCVSS 9.8EG 9.82026-05-21
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route — /fission-functi…
- CVE-2026-8495CRITICALCVSS 9.8EG 9.82026-05-19
Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.
- CVE-2026-41315CRITICALCVSS 9.8EG 9.82026-05-14
mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possibl…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →