CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
10,777 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 4 of 216
- CVE-2026-6510CRITICALCVSS 9.8EG 9.82026-05-14
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() …
- CVE-2026-26083CRITICALCVSS 9.8EG 9.82026-05-12
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSa…
- CVE-2021-47932CRITICALCVSS 9.8EG 9.82026-05-10
WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to th…
- CVE-2026-43575CRITICALCVSS 9.8EG 9.82026-05-06
OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge …
- CVE-2026-5294CRITICALCVSS 9.8EG 9.82026-05-05
The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispatch and reaching a plugin installer help…
- CVE-2026-6235CRITICALCVSS 9.8EG 9.82026-04-22
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is…
- CVE-2026-3596CRITICALCVSS 9.8EG 9.82026-04-16
The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopriv_install-imprint') that maps to the in…
- CVE-2026-40189CRITICALCVSS 9.8EG 9.82026-04-10
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for sta…
- CVE-2026-1830CRITICALCVSS 9.8EG 9.82026-04-09
The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrar…
- CVE-2026-33229CRITICALCVSS 9.8EG 9.82026-04-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the V…
- CVE-2026-4003CRITICALCVSS 9.8EG 9.82026-04-08
The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the userspn_ajax_nopriv_ser…
- CVE-2026-39397CRITICALCVSS 9.8EG 9.82026-04-07
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAcce…
- CVE-2026-4277CRITICALCVSS 9.8EG 9.82026-04-07
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Dja…
- CVE-2026-35561CRITICALCVSS 9.8EG 9.82026-04-03
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protecti…
- CVE-2026-4038CRITICALCVSS 9.8EG 9.82026-03-20
The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including…
- CVE-2026-29515CRITICALCVSS 9.8EG 9.82026-03-11
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinati…
- CVE-2026-30968CRITICALCVSS 9.8EG 9.82026-03-10
Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, the SSE endpoint (/sse/v1/...) in Coral Server did not strongly validate that a conn…
- CVE-2026-2446CRITICALCVSS 9.8EG 9.82026-03-06
The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary a…
- CVE-2026-3266CRITICALCVSS 9.8EG 9.82026-03-03
Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1…
- CVE-2026-3431CRITICALCVSS 9.8EG 9.82026-03-02
On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable Mongo…
- CVE-2026-28408CRITICALCVSS 9.8EG 9.82026-02-27
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its own authentication and permission checks.…
- CVE-2026-2039CRITICALCVSS 9.8EG 9.82026-02-20
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit thi…
- CVE-2026-2038CRITICALCVSS 9.8EG 9.82026-02-20
GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this…
- CVE-2026-25242CRITICALCVSS 9.8EG 9.82026-02-19
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any remote user can upload arbitrary files …
- CVE-2025-70150CRITICALCVSS 9.8EG 9.82026-02-18
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
- CVE-2025-69052CRITICALCVSS 9.8EG 9.82026-01-22
Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registration-login-with-mobile-phone-number allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…
- CVE-2026-24042CRITICALCVSS 9.8EG 9.82026-01-22
Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthenticated users to execute unpublished (edit-mode) actions by sending viewMode=false (or omittin…
- CVE-2021-47812CRITICALCVSS 9.8EG 9.82026-01-16
GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base…
- CVE-2025-39477CRITICALCVSS 9.8EG 9.82026-01-06
Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8.
- CVE-2025-15115CRITICALCVSS 9.8EG 9.82026-01-04
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system…
- CVE-2023-54327CRITICALCVSS 9.8EG 9.82025-12-30
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially cr…
- CVE-2025-15068CRITICALCVSS 9.8EG 9.82025-12-29
Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification through Manipulation.This issue affects Web Fax: from 3.0 before 3.0.1
- CVE-2023-53923CRITICALCVSS 9.8EG 9.82025-12-17
UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php wit…
- CVE-2025-12963CRITICALCVSS 9.8EG 9.82025-12-12
The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.29. This is due to the plugin …
- CVE-2023-53740CRITICALCVSS 9.8EG 9.82025-12-10
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON…
- CVE-2020-36902CRITICALCVSS 9.8EG 9.82025-12-10
UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' s…
- CVE-2025-13313CRITICALCVSS 9.8EG 9.82025-12-05
The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due to missing authorization and authentication checks on the `ntzcrm_changepassword` AJAX…
- CVE-2025-13342CRITICALCVSS 9.8EG 9.82025-12-03
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validati…
- CVE-2025-65112CRITICALCVSS 9.8EG 9.82025-11-29
PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables id…
- CVE-2025-66022CRITICALCVSS 9.8EG 9.82025-11-26
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension framework permits untrusted extension code to execute arbitrary system commands on the serv…
- CVE-2025-12925CRITICALCVSS 9.8EG 9.82025-11-10
A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. Th…
- CVE-2025-12158CRITICALCVSS 9.8EG 9.82025-11-04
The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabilities() function in all versions up to, and including, 1.0. This makes it possible for unaut…
- CVE-2025-11833CRITICALCVSS 9.8EG 9.82025-11-01
The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and…
- CVE-2024-13994CRITICALCVSS 9.8EG 9.82025-10-30
Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper auth…
- CVE-2025-59461CRITICALCVSS 9.8EG 9.82025-10-27
A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.
- CVE-2025-59827CRITICALCVSS 9.8EG 9.82025-09-24
Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign high-privilege badges (e.g., Staff) to themselves. This could le…
- CVE-2025-59828CRITICALCVSS 9.8EG 9.82025-09-24
Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.0+, Yarn plugins are auto-executed when running yarn --version. This could lead to a bypass of the directory trust dial…
- CVE-2025-9054CRITICALCVSS 9.8EG 9.82025-09-24
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'wcmlim_settings_ajax_h…
- CVE-2025-10690CRITICALCVSS 9.8EG 9.82025-09-19
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability check on the 'beplus_import_pack_install_plugin' function in all versions up to, and includin…
- CVE-2024-32832CRITICALCVSS 9.8EG 9.82025-08-31
Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →