CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

7,701 vulnerabilities with CWE-862
CVE-2026-22683 HIGH
Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE
CVSS 8.8
CVE-2026-4292 LOW
Privilege abuse in ModelAdmin.list_editable
CVSS 2.7
CVE-2026-4277 CRITICAL
Privilege abuse in GenericInlineModelAdmin
CVSS 9.8
CVE-2026-33866 MEDIUM
Authorization Bypass in MLflow AJAX Endpoint
CVSS 4.3
CVE-2026-34903 MEDIUM
WordPress Ocean Extra plugin <= 2.5.3 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-34899 MEDIUM
WordPress LTL Freight Quotes – Worldwide Express Edition plugin <= 5.2.1 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-35448 LOW
WWBN AVideo Provides Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php
CVSS 3.7
CVE-2026-35182 HIGH
Missing Authorization Privilege Escalation
CVSS 8.8
CVE-2026-35179 MEDIUM
WWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php
CVSS 5.3
CVE-2026-35175 MEDIUM
Ajenti has an authorization bypass during custom package installation
CVSS 6.5
CVE-2026-34976 CRITICAL
Dgraph Affected by Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
CVSS 10.0
CVE-2026-3524 HIGH
Authorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission Check
CVSS 8.8
CVE-2026-5624 MEDIUM
ProjectSend upload.php cross-site request forgery
CVSS 4.3
CVE-2026-5574 MEDIUM
Technostrobe HI-LED-WR120-G2 FsBrowseClean deletefile authorization
CVSS 6.5
CVE-2026-5572 MEDIUM
Technostrobe HI-LED-WR120-G2 cross-site request forgery
CVSS 4.3
CVE-2026-3445 HIGH
ProfilePress < 4.16.11 - Payment Bypass
CVSS 7.1
CVE-2026-2826 MEDIUM
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload
CVSS 4.3
CVE-2026-3571 MEDIUM
Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization to Unauthenticated Registration Form Status Modification
CVSS 6.5
CVE-2026-34766 LOW
Electron: USB device selection not validated against filtered device list
CVSS 3.3
CVE-2026-27833 HIGH
Piwigo: Unauthenticated Information Disclosure via pwg.history.search API
CVSS 7.5
CVE-2026-35561 HIGH
Insufficient authentication security controls in browser-based authentication components in Amazon Athena ODBC driver
CVSS 7.4
CVE-2026-25742 MEDIUM
Zulip: Anonymous File Access After Disabling Spectator Access
CVSS 5.3
CVE-2026-22663 HIGH
prompts.chat Authorization Bypass Information Disclosure
CVSS 7.5
CVE-2026-34759 HIGH
OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposure
CVSS 8.1
CVE-2026-33950 CRITICAL
signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity
CVSS 9.4
Details
Vulnerabilities 7,701
Exploit Likelihood High