CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,799 vulnerabilities with CWE-862
CVE-2026-18437 MEDIUM
MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates
CVSS 5.3
CVE-2026-18436 MEDIUM
MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Modification via REST API Endpoint
CVSS 5.3
CVE-2026-18218 MEDIUM
Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero
CVSS 4.2
CVE-2026-18214 MEDIUM
Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction
CVSS 6.8
CVE-2026-18208 MEDIUM
Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim
CVSS 6.5
CVE-2026-67529 MEDIUM
OpenProject < 17.6.0 - Private Work Package Information Disclosure
CVSS 4.3
CVE-2026-67527 HIGH
OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter "fileLinks"
CVSS 7.6
CVE-2026-15397 HIGH
Subscriptions for WooCommerce <= 2.0.0 - Authenticated Arbitrary Plugin Installation
CVSS 7.2
CVE-2026-15252 MEDIUM
Search Atlas SEO < 2.6.12 - Subscriber+ Google Indexing API Access
CVSS 5.4
CVE-2026-15054 LOW
Bit Form < 3.1.2 - Unauthenticated Inactive Form Submission
CVSS 3.7
CVE-2026-12500 HIGH
WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update
CVSS 7.5
CVE-2026-11867 MEDIUM
Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization
CVSS 6.5
CVE-2026-14356 HIGH
FleekDash V2 <= 2.6.2.2 - Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover via /users/{id} REST Endpoint
CVSS 8.8
CVE-2026-4672 MEDIUM
Missing Authorization in GitLab
CVSS 4.3
CVE-2026-14341 MEDIUM
Missing Authorization in GitLab
CVSS 4.9
CVE-2026-16543 HIGH
Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-certificate ID collision
CVE-2026-15228 HIGH
Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via CA-certificate ID collision
CVE-2026-66724 MEDIUM
Permission Bypass Via Undocumented HTTP Methods In MWDB Core
CVE-2026-66723 HIGH
Missing authentication requirement in Remote Instances proxy API in MWDB Core
CVE-2026-4604 MEDIUM
Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update
CVSS 5.3
CVE-2026-14488 CRITICAL
Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter
CVSS 9.1
CVE-2026-50622 HIGH
Apache Atlas: Missing Authorization on Admin Endpoints
CVSS 8.8
CVE-2026-18201 MEDIUM
Red Hat Build of Keycloak - Unauthorized Identity Provider Organization Binding
CVSS 5.5
CVE-2026-13692 MEDIUM
PayU CommercePro <= 3.8.9 - Unauthenticated Order Tampering
CVSS 5.3
CVE-2026-5626 MEDIUM
Survey Form Block <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission Data Export
CVSS 4.3
Details
Vulnerabilities 8,799
Exploit Likelihood High