CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,140 vulnerabilities with CWE-862
CVE-2026-9486 MEDIUM
SourceCodester Student Grades Management System cross-site request forgery
CVSS 4.3
CVE-2026-24546 MEDIUM
WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-2651 CRITICAL
Missing Authorization Validation in mlflow/mlflow
CVSS 9.0
CVE-2026-9350 HIGH
NousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorization
CVSS 7.3
CVE-2026-9303 MEDIUM
calcom cal.diy cross-site request forgery
CVSS 4.3
CVE-2026-9284 HIGH
WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure
CVSS 8.2
CVE-2026-3294 HIGH
Authentication Logic Vulnerability on Multiple TP-Link Range Extenders
CVSS 8.8
CVE-2026-39967 LOW
TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter
CVSS 3.1
CVE-2026-9255 HIGH
Tool Execution Without Authorization via Piped Stdin in Kiro CLI
CVSS 7.8
CVE-2026-33712 CRITICAL
TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls
CVSS 10.0
CVE-2026-9251 MEDIUM
Devolutions Server - Missing Authorization
CVSS 5.4
CVE-2026-9246 MEDIUM
Devolutions Server - Missing Authorization
CVSS 4.3
CVE-2026-9224 MEDIUM
Devolutions Server - Missing Authorization
CVSS 4.3
CVE-2026-9011 HIGH
Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via ditty_init AJAX Action
CVSS 7.5
CVE-2026-8692 MEDIUM
Vedrixa Forms <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Structure Modification via wefb_save_form_structure AJAX Action
CVSS 4.3
CVE-2026-8684 MEDIUM
MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action
CVSS 5.3
CVE-2026-8381 MEDIUM
Broken Access Control in TeamViewer DEX Platform (On Premises)
CVSS 5.4
CVE-2026-7249 MEDIUM
Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contributor+) Block Settings Modification and Cache Purging
CVSS 4.3
CVE-2026-44409 MEDIUM
ZTE MU5250 - Unauthorized Information Disclosure
CVSS 5.7
CVE-2026-2518 MEDIUM
FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation and Activation
CVSS 4.3
CVE-2026-39833 CRITICAL
Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
CVSS 9.1
CVE-2026-39831 CRITICAL
Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
CVSS 9.1
CVE-2026-8239 MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
CVSS 5.3
CVE-2026-8238 MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing unauthenticated read of any conversation message
CVSS 5.3
CVE-2026-8237 MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
CVSS 5.3
Details
Vulnerabilities 8,140
Exploit Likelihood High