The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,794 vulnerabilities with CWE-862
CVE-2026-67529
MEDIUM
OpenProject < 17.6.0 - Private Work Package Information Disclosure
CVSS 4.3
CVE-2026-67527
HIGH
OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks"
CVSS 7.6
CVE-2026-15397
HIGH
Subscriptions for WooCommerce <= 2.0.0 - Authenticated Arbitrary Plugin Installation
CVSS 7.2
CVE-2026-15252
MEDIUM
Search Atlas SEO < 2.6.12 - Subscriber+ Google Indexing API Access
CVSS 5.4
CVE-2026-15054
LOW
Bit Form < 3.1.2 - Unauthenticated Inactive Form Submission
CVSS 3.7
CVE-2026-12500
HIGH
WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update
CVSS 7.5
CVE-2026-11867
MEDIUM
Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization
CVSS 6.5
CVE-2026-14356
HIGH
FleekDash V2 <= 2.6.2.2 - Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover via /users/{id} REST Endpoint
CVSS 8.8
CVE-2026-4672
MEDIUM
Missing Authorization in GitLab
CVSS 4.3
CVE-2026-14341
MEDIUM
Missing Authorization in GitLab
CVSS 4.9
CVE-2026-16543
HIGH
Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-certificate ID collision
CVE-2026-15228
HIGH
Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via CA-certificate ID collision
CVE-2026-66724
MEDIUM
Permission Bypass Via Undocumented HTTP Methods In MWDB Core
CVE-2026-66723
HIGH
Missing authentication requirement in Remote Instances proxy API in MWDB Core
CVE-2026-4604
MEDIUM
Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update
CVSS 5.3
CVE-2026-14488
CRITICAL
Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter
CVSS 9.1
CVE-2026-50622
HIGH
Apache Atlas: Missing Authorization on Admin Endpoints
CVSS 8.8
CVE-2026-18201
MEDIUM
Red Hat Build of Keycloak - Unauthorized Identity Provider Organization Binding
CVSS 5.5
CVE-2026-13692
MEDIUM
PayU CommercePro <= 3.8.9 - Unauthenticated Order Tampering
CVSS 5.3
CVE-2026-5626
MEDIUM
Survey Form Block <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission Data Export
CVSS 4.3
CVE-2026-17166
MEDIUM
Event Booking Manager For WooCommerce < 5.3.7 - Authorization Bypass
CVSS 4.3
CVE-2026-54719
HIGH
goshs < 2.1.1 - Unauthenticated Bulk Download ACL Bypass
CVSS 7.5
CVE-2026-16184
HIGH
IBM WebSphere Application Server is affected by an authentication bypass
CVSS 7.0
CVE-2026-49258
HIGH
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
CVSS 8.8
CVE-2026-66751
MEDIUM
Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
CVSS 5.4
Details
Vulnerabilities
8,794
Exploit Likelihood
High