The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
7,701 vulnerabilities with CWE-862
CVE-2026-22683
HIGH
Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE
CVSS 8.8
CVE-2026-4292
LOW
Privilege abuse in ModelAdmin.list_editable
CVSS 2.7
CVE-2026-4277
CRITICAL
Privilege abuse in GenericInlineModelAdmin
CVSS 9.8
CVE-2026-33866
MEDIUM
Authorization Bypass in MLflow AJAX Endpoint
CVSS 4.3
CVE-2026-34903
MEDIUM
WordPress Ocean Extra plugin <= 2.5.3 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-34899
MEDIUM
WordPress LTL Freight Quotes – Worldwide Express Edition plugin <= 5.2.1 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-35448
LOW
WWBN AVideo Provides Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php
CVSS 3.7
CVE-2026-35182
HIGH
Missing Authorization Privilege Escalation
CVSS 8.8
CVE-2026-35179
MEDIUM
WWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php
CVSS 5.3
CVE-2026-35175
MEDIUM
Ajenti has an authorization bypass during custom package installation
CVSS 6.5
CVE-2026-34976
CRITICAL
Dgraph Affected by Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
CVSS 10.0
CVE-2026-3524
HIGH
Authorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission Check
CVSS 8.8
CVE-2026-5624
MEDIUM
ProjectSend upload.php cross-site request forgery
CVSS 4.3
CVE-2026-5574
MEDIUM
Technostrobe HI-LED-WR120-G2 FsBrowseClean deletefile authorization
CVSS 6.5
CVE-2026-5572
MEDIUM
Technostrobe HI-LED-WR120-G2 cross-site request forgery
CVSS 4.3
CVE-2026-3445
HIGH
ProfilePress < 4.16.11 - Payment Bypass
CVSS 7.1
CVE-2026-2826
MEDIUM
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload
CVSS 4.3
CVE-2026-3571
MEDIUM
Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization to Unauthenticated Registration Form Status Modification
CVSS 6.5
CVE-2026-34766
LOW
Electron: USB device selection not validated against filtered device list
CVSS 3.3
CVE-2026-27833
HIGH
Piwigo: Unauthenticated Information Disclosure via pwg.history.search API
CVSS 7.5
CVE-2026-35561
HIGH
Insufficient authentication security controls in browser-based authentication components in Amazon Athena ODBC driver
CVSS 7.4
CVE-2026-25742
MEDIUM
Zulip: Anonymous File Access After Disabling Spectator Access
CVSS 5.3
CVE-2026-22663
HIGH
prompts.chat Authorization Bypass Information Disclosure
CVSS 7.5
CVE-2026-34759
HIGH
OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposure
CVSS 8.1
CVE-2026-33950
CRITICAL
signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity
CVSS 9.4
Details
Vulnerabilities
7,701
Exploit Likelihood
High