CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,807 vulnerabilities with CWE-862
CVE-2026-13039 MEDIUM
Eventin 4.0.26-4.1.15 - Unauthenticated Payment Bypass
CVSS 5.3
CVE-2026-57850 HIGH
RustDesk before 1.4.9 Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
CVSS 8.3
CVE-2026-55476 MEDIUM
Snipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
CVSS 4.3
CVE-2026-54329 HIGH
Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API
CVSS 8.5
CVE-2026-56668 HIGH
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
CVSS 8.1
CVE-2026-55638 HIGH
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
CVSS 8.6
CVE-2026-1667 HIGH
SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()
CVSS 7.2
CVE-2026-61441 MEDIUM
PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies
CVSS 6.5
CVE-2026-59796 HIGH
Jetbrains TeamCity < 2026.1.2 - Missing Authorization
CVSS 8.1
CVE-2026-56279 HIGH
Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint
CVSS 7.5
CVE-2026-9857 MEDIUM
Invoice123 < 1.7.0 - Authorization Bypass
CVSS 4.3
CVE-2026-11990 MEDIUM
KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint
CVSS 5.3
CVE-2026-1946 MEDIUM
GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion
CVSS 4.3
CVE-2026-15026 MEDIUM
Import And Export Users And Customers < 2.4.0 - Information Exposure
CVSS 4.3
CVE-2026-12955 MEDIUM
Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action
CVSS 4.3
CVE-2026-11992 MEDIUM
Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation
CVSS 4.3
CVE-2026-15332 MEDIUM
zhayujie CowAgent Message Endpoint channel.py authorization
CVSS 6.3
CVE-2026-15293 HIGH
WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification
CVSS 8.0
CVE-2026-15291 HIGH
Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
CVSS 7.5
CVE-2026-44918 MEDIUM
Openstack Ironic - Missing Authorization
CVSS 5.5
CVE-2026-11818 MEDIUM
WPCafe <= 3.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API
CVSS 5.4
CVE-2026-15320 MEDIUM
Sipeed PicoClaw pico.go rt.ReloadConfig authorization
CVSS 5.4
CVE-2026-59853 MEDIUM
SiYuan < 3.7.1 Publish Mode - Private Saved Search Disclosure
CVSS 6.5
CVE-2026-46413 MEDIUM
Discourse: Regular users can route multipart uploads into the admin backup store
CVSS 6.5
CVE-2026-33802 MEDIUM
Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command
CVSS 5.5
Details
Vulnerabilities 8,807
Exploit Likelihood High