The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
7,700 vulnerabilities with CWE-862
CVE-2026-3143
MEDIUM
Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback Cancellation
CVSS 5.3
CVE-2026-40601
HIGH
Chartbrew: Missing Authorization in /api/chart/:chart_id/query via team-level refresh toggle
CVSS 7.5
CVE-2026-42522
MEDIUM
Jenkins GitHub Branch Source Plugin <=1967.vdea_d580c1a_b_a_ - Auth Bypass
CVSS 4.3
CVE-2026-42519
MEDIUM
Jenkins Script Security Plugin <=1399.ve6a_66547f6e1 - Info Disclosure
CVSS 4.3
CVE-2026-42648
MEDIUM
WordPress Spectra plugin <= 2.19.22 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-42642
MEDIUM
WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-4019
MEDIUM
Complianz – GDPR/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated Private Post Content Disclosure via Consent Area REST Endpoint
CVSS 5.3
CVE-2026-42412
MEDIUM
WordPress WP User Frontend plugin <= 4.3.1 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-42377
HIGH
WordPress SureForms Pro plugin <= 2.8.0 - Broken Access Control vulnerability
CVSS 7.3
CVE-2026-41394
HIGH
OpenClaw < 2026.3.31 - Unauthorized Operator Scope Access in Unauthenticated Plugin-Auth Routes
CVSS 8.2
CVE-2026-41382
MEDIUM
OpenClaw < 2026.3.31 - Discord Voice Ingress Authorization Bypass via Channel and Role Validation Gaps
CVSS 5.4
CVE-2026-41378
HIGH
OpenClaw < 2026.3.31 - Privilege Escalation to Remote Code Execution via Unrestricted node.event Agent Dispatch
CVSS 8.8
CVE-2026-6706
MEDIUM
Devolutions Server <=2026.1.14.0 - Auth Bypass
CVSS 6.5
CVE-2026-5944
HIGH
Cisco Intersight Device Connector for Nutanix Prism Central Unauthenticated API Access
CVSS 8.2
CVE-2026-40976
CRITICAL
Spring Boot 4.0.0-4.0.5 - Auth Bypass
CVSS 9.1
CVE-2026-41464
MEDIUM
ProjeQtor < 12.4.4 Missing Authorization via objectDetail.php
CVSS 6.5
CVE-2026-7108
MEDIUM
code-projects Invoice System in Laravel cross-site request forgery
CVSS 4.3
CVE-2026-41477
HIGH
Deskflow: Local privilege escalation via unauthenticated IPC
CVSS 7.8
CVE-2026-3569
MEDIUM
Liaison Site Prober <= 1.2.1 - Missing Authorization to Unauthenticated Information Exposure in '/logs' REST API Endpoint
CVSS 5.3
CVE-2026-5347
MEDIUM
WP Books Gallery <= 4.8.0 - Missing Authorization to Unauthenticated Settings Update via 'permalink_structure' Parameter
CVSS 5.3
CVE-2026-6393
MEDIUM
BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage
CVSS 4.3
CVE-2026-5488
MEDIUM
ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token'
CVSS 5.3
CVE-2026-33318
HIGH
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
CVSS 8.8
CVE-2026-40623
HIGH
SenseLive X3050 Missing Authorization
CVSS 8.1
CVE-2026-41352
HIGH
OpenClaw < 2026.3.31 - Remote Code Execution via Node Scope Gate Bypass
CVSS 8.8
Details
Vulnerabilities
7,700
Exploit Likelihood
High