CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,140 vulnerabilities with CWE-862
CVE-2026-45242 HIGH
Summarize < 0.15.1 Path Traversal via slidesDir Parameter
CVSS 7.1
CVE-2026-5163 MEDIUM
Missing authorization check in AI message rewrite endpoint allows access to private thread content
CVSS 6.5
CVE-2026-3117 MEDIUM
Instance and webhook GitLab plugin commands were able to be run by non-admin users
CVSS 6.5
CVE-2026-3637 MEDIUM
Mattermost fails to enforce create_post permission when editing posts
CVSS 4.3
CVE-2026-1631 MEDIUM
Feeds for YouTube < 2.6.4 - Subscriber+ License Data Deletion
CVSS 5.4
CVE-2026-8681 MEDIUM
Essential Chat Support <= 1.0.1 - Missing Authorization to Unauthenticated Settings Reset via 'ecs_reset_settings' Parameter
CVSS 5.3
CVE-2026-45667 MEDIUM
Open WebUI Memories Endpoint - Unauthenticated Embedding Generation DoS
CVSS 6.5
CVE-2026-45350 HIGH
Open WebUI: Chat completion API allows tool restrictions to be bypassed
CVSS 7.1
CVE-2026-44571 MEDIUM
Open WebUI: Improper Authorization in Standard Channels Allows Message Updates with Read Permission
CVSS 6.5
CVE-2026-44569 HIGH
Open WebUI: Insecure Message Access Breaks Authorization
CVSS 7.1
CVE-2026-45395 HIGH
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
CVSS 7.2
CVE-2026-45399 HIGH
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
CVSS 7.1
CVE-2026-44563 MEDIUM
Open WebUI: Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
CVSS 5.4
CVE-2026-44562 MEDIUM
Open WebUI: Model Import Overwrites Any Model Without Ownership Check
CVSS 6.5
CVE-2026-44560 MEDIUM
Open WebUI: Unauthorized File and Knowledge Base Content Access via RAG Vector Search
CVSS 6.5
CVE-2026-44559 MEDIUM
Open WebUI: Missing Access Check on Channel Members Endpoint for Standard Channels
CVSS 4.3
CVE-2026-44558 MEDIUM
Open WebUI: Channel Access Grants Bypass filter_allowed_access_grants
CVSS 5.4
CVE-2026-44556 HIGH
Open WebUI: responses passthrough endpoint lacks access control authorization
CVSS 7.1
CVE-2026-44555 HIGH
Open WebUI: Base Model Routing Bypasses Access Control via Model Chaining
CVSS 7.6
CVE-2026-44554 HIGH
Open WebUI: Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
CVSS 8.1
CVE-2026-44550 MEDIUM
Open WebUI: Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
CVSS 5.0
CVE-2026-46365 MEDIUM
phpMyFAQ - Missing Authorization in Tag Deletion Endpoint
CVSS 5.4
CVE-2026-45007 MEDIUM
phpMyFAQ - Missing Permission Check on 12 Configuration API Endpoints Allows Information Disclosure
CVSS 4.3
CVE-2026-44719 MEDIUM
Mathesar: Missing collaborator checks allowed access to database-scoped Mathesar metadata
CVE-2026-44718 MEDIUM
Mathesar: Missing collaborator checks allowed access to saved explorations in other databases
Details
Vulnerabilities 8,140
Exploit Likelihood High