CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,804 vulnerabilities with CWE-862
CVE-2026-62194 HIGH
OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install
CVSS 8.8
CVE-2026-62191 HIGH
OpenClaw 2026.6.6 < 2026.6.8 Authorization Bypass via Message Mutations
CVSS 7.1
CVE-2026-62186 HIGH
OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override
CVSS 7.6
CVE-2026-58410 HIGH
ChurchCRM < 7.4.0 - Authenticated Family Record Access Control Bypass
CVSS 7.1
CVE-2026-58408 MEDIUM
ChurchCRM < 7.4.0 CSVCreateFile.php - Unauthorized Member PII Export
CVSS 6.5
CVE-2026-9824 MEDIUM
Mattermost - Remote Cluster Metadata Enumeration via /share-channel Autocomplete
CVSS 4.3
CVE-2026-9820 LOW
Mattermost schemes teams endpoint exposes private team invite IDs
CVSS 3.8
CVE-2026-14934 CRITICAL
Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise
CVE-2026-61985 MEDIUM
WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-61983 MEDIUM
WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-61968 MEDIUM
WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-61958 MEDIUM
WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Content Deletion vulnerability
CVSS 5.4
CVE-2026-61952 MEDIUM
WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 - Broken Access Control vulnerability
CVSS 4.9
CVE-2026-59523 MEDIUM
WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57812 MEDIUM
WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57797 MEDIUM
WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-57782 MEDIUM
WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57781 MEDIUM
WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57779 MEDIUM
WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57778 MEDIUM
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57776 MEDIUM
WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57774 MEDIUM
WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57740 HIGH
WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability
CVSS 7.1
CVE-2026-57729 HIGH
WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-57727 HIGH
WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability
CVSS 7.5
Details
Vulnerabilities 8,804
Exploit Likelihood High