CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

7,700 vulnerabilities with CWE-862
CVE-2026-3143 MEDIUM
Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback Cancellation
CVSS 5.3
CVE-2026-40601 HIGH
Chartbrew: Missing Authorization in /api/chart/:chart_id/query via team-level refresh toggle
CVSS 7.5
CVE-2026-42522 MEDIUM
Jenkins GitHub Branch Source Plugin <=1967.vdea_d580c1a_b_a_ - Auth Bypass
CVSS 4.3
CVE-2026-42519 MEDIUM
Jenkins Script Security Plugin <=1399.ve6a_66547f6e1 - Info Disclosure
CVSS 4.3
CVE-2026-42648 MEDIUM
WordPress Spectra plugin <= 2.19.22 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-42642 MEDIUM
WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-4019 MEDIUM
Complianz – GDPR/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated Private Post Content Disclosure via Consent Area REST Endpoint
CVSS 5.3
CVE-2026-42412 MEDIUM
WordPress WP User Frontend plugin <= 4.3.1 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-42377 HIGH
WordPress SureForms Pro plugin <= 2.8.0 - Broken Access Control vulnerability
CVSS 7.3
CVE-2026-41394 HIGH
OpenClaw < 2026.3.31 - Unauthorized Operator Scope Access in Unauthenticated Plugin-Auth Routes
CVSS 8.2
CVE-2026-41382 MEDIUM
OpenClaw < 2026.3.31 - Discord Voice Ingress Authorization Bypass via Channel and Role Validation Gaps
CVSS 5.4
CVE-2026-41378 HIGH
OpenClaw < 2026.3.31 - Privilege Escalation to Remote Code Execution via Unrestricted node.event Agent Dispatch
CVSS 8.8
CVE-2026-6706 MEDIUM
Devolutions Server <=2026.1.14.0 - Auth Bypass
CVSS 6.5
CVE-2026-5944 HIGH
Cisco Intersight Device Connector for Nutanix Prism Central Unauthenticated API Access
CVSS 8.2
CVE-2026-40976 CRITICAL
Spring Boot 4.0.0-4.0.5 - Auth Bypass
CVSS 9.1
CVE-2026-41464 MEDIUM
ProjeQtor < 12.4.4 Missing Authorization via objectDetail.php
CVSS 6.5
CVE-2026-7108 MEDIUM
code-projects Invoice System in Laravel cross-site request forgery
CVSS 4.3
CVE-2026-41477 HIGH
Deskflow: Local privilege escalation via unauthenticated IPC
CVSS 7.8
CVE-2026-3569 MEDIUM
Liaison Site Prober <= 1.2.1 - Missing Authorization to Unauthenticated Information Exposure in '/logs' REST API Endpoint
CVSS 5.3
CVE-2026-5347 MEDIUM
WP Books Gallery <= 4.8.0 - Missing Authorization to Unauthenticated Settings Update via 'permalink_structure' Parameter
CVSS 5.3
CVE-2026-6393 MEDIUM
BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage
CVSS 4.3
CVE-2026-5488 MEDIUM
ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token'
CVSS 5.3
CVE-2026-33318 HIGH
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
CVSS 8.8
CVE-2026-40623 HIGH
SenseLive X3050 Missing Authorization
CVSS 8.1
CVE-2026-41352 HIGH
OpenClaw < 2026.3.31 - Remote Code Execution via Node Scope Gate Bypass
CVSS 8.8
Details
Vulnerabilities 7,700
Exploit Likelihood High