The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,804 vulnerabilities with CWE-862
CVE-2026-53444
HIGH
Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to admin
CVE-2026-52892
MEDIUM
Wekan < 9.32 Custom Fields API - Read-Only Member Privilege Escalation
CVSS 6.5
CVE-2026-54052
CRITICAL
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
CVSS 9.9
CVE-2026-33684
MEDIUM
WWBN AVideo < 29.0 signUp API - Permission Self-Grant Privilege Escalation
CVSS 5.3
CVE-2026-56742
MEDIUM
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
CVSS 5.9
CVE-2026-52870
HIGH
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
CVSS 7.6
CVE-2026-62348
MEDIUM
TDengine: KILL SSMIGRATE missing authorization lets low-privilege users interrupt shared-storage migrations
CVSS 5.4
CVE-2026-59255
HIGH
BloodHound Missing Authorization on Custom Node Management API
CVSS 7.1
CVE-2026-53514
HIGH
Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin
CVSS 7.7
CVE-2026-46459
MEDIUM
Missing Authorization in ICU Scandinavia Boomerang
CVE-2026-61440
MEDIUM
PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints
CVSS 6.5
CVE-2026-14251
HIGH
Red Hat OpenShift GitOps Operator - ClusterRole Deletion Denial of Service
CVSS 7.7
CVE-2026-15752
HIGH
zhinianboke xianyu-auto-reply Backend User Endpoint users authorization
CVSS 7.3
CVE-2026-53633
CRITICAL
Vitest Browser Mode - Remote Code Execution via Exposed CDP API
CVSS 9.8
CVE-2026-55052
HIGH
Microsoft SharePoint Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-58279
MEDIUM
Azure CycleCloud Elevation of Privilege Vulnerability
CVSS 6.5
CVE-2026-60119
MEDIUM
Hi.Events v1.10.0-beta XSS via Event Title JSON.stringify Injection
CVSS 5.4
CVE-2026-60118
MEDIUM
Hi.Events v1.10.0-beta Hidden Ticket Enumeration via Order Creation Endpoint
CVSS 5.3
CVE-2026-52839
LOW
Easy!Appointments < 1.6.0 - Cross-Provider Appointment Authorization Bypass
CVSS 3.3
CVE-2026-14504
HIGH
Nexus Repository 3 - Authorization Bypass in Component Upload API
CVE-2026-12988
MEDIUM
WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding
CVSS 6.4
CVE-2026-11802
MEDIUM
FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Registration via 'registration_action' AJAX Action
CVSS 5.3
CVE-2026-44771
MEDIUM
Missing Authorization check in SAP S/4HANA (Draft operation)
CVSS 4.3
CVE-2026-44770
MEDIUM
Missing Authorization check in SAP S/4 HANA (Create Single Payment)
CVSS 4.3
CVE-2026-62328
HIGH
9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
CVSS 7.5
Details
Vulnerabilities
8,804
Exploit Likelihood
High