CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,804 vulnerabilities with CWE-862
CVE-2026-53444 HIGH
Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to admin
CVE-2026-52892 MEDIUM
Wekan < 9.32 Custom Fields API - Read-Only Member Privilege Escalation
CVSS 6.5
CVE-2026-54052 CRITICAL
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
CVSS 9.9
CVE-2026-33684 MEDIUM
WWBN AVideo < 29.0 signUp API - Permission Self-Grant Privilege Escalation
CVSS 5.3
CVE-2026-56742 MEDIUM
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
CVSS 5.9
CVE-2026-52870 HIGH
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
CVSS 7.6
CVE-2026-62348 MEDIUM
TDengine: KILL SSMIGRATE missing authorization lets low-privilege users interrupt shared-storage migrations
CVSS 5.4
CVE-2026-59255 HIGH
BloodHound Missing Authorization on Custom Node Management API
CVSS 7.1
CVE-2026-53514 HIGH
Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin
CVSS 7.7
CVE-2026-46459 MEDIUM
Missing Authorization in ICU Scandinavia Boomerang
CVE-2026-61440 MEDIUM
PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints
CVSS 6.5
CVE-2026-14251 HIGH
Red Hat OpenShift GitOps Operator - ClusterRole Deletion Denial of Service
CVSS 7.7
CVE-2026-15752 HIGH
zhinianboke xianyu-auto-reply Backend User Endpoint users authorization
CVSS 7.3
CVE-2026-53633 CRITICAL
Vitest Browser Mode - Remote Code Execution via Exposed CDP API
CVSS 9.8
CVE-2026-55052 HIGH
Microsoft SharePoint Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-58279 MEDIUM
Azure CycleCloud Elevation of Privilege Vulnerability
CVSS 6.5
CVE-2026-60119 MEDIUM
Hi.Events v1.10.0-beta XSS via Event Title JSON.stringify Injection
CVSS 5.4
CVE-2026-60118 MEDIUM
Hi.Events v1.10.0-beta Hidden Ticket Enumeration via Order Creation Endpoint
CVSS 5.3
CVE-2026-52839 LOW
Easy!Appointments < 1.6.0 - Cross-Provider Appointment Authorization Bypass
CVSS 3.3
CVE-2026-14504 HIGH
Nexus Repository 3 - Authorization Bypass in Component Upload API
CVE-2026-12988 MEDIUM
WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding
CVSS 6.4
CVE-2026-11802 MEDIUM
FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Registration via 'registration_action' AJAX Action
CVSS 5.3
CVE-2026-44771 MEDIUM
Missing Authorization check in SAP S/4HANA (Draft operation)
CVSS 4.3
CVE-2026-44770 MEDIUM
Missing Authorization check in SAP S/4 HANA (Create Single Payment)
CVSS 4.3
CVE-2026-62328 HIGH
9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
CVSS 7.5
Details
Vulnerabilities 8,804
Exploit Likelihood High