The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,807 vulnerabilities with CWE-862
CVE-2026-13039
MEDIUM
Eventin 4.0.26-4.1.15 - Unauthenticated Payment Bypass
CVSS 5.3
CVE-2026-57850
HIGH
RustDesk before 1.4.9 Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
CVSS 8.3
CVE-2026-55476
MEDIUM
Snipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
CVSS 4.3
CVE-2026-54329
HIGH
Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API
CVSS 8.5
CVE-2026-56668
HIGH
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
CVSS 8.1
CVE-2026-55638
HIGH
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
CVSS 8.6
CVE-2026-1667
HIGH
SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()
CVSS 7.2
CVE-2026-61441
MEDIUM
PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies
CVSS 6.5
CVE-2026-59796
HIGH
Jetbrains TeamCity < 2026.1.2 - Missing Authorization
CVSS 8.1
CVE-2026-56279
HIGH
Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint
CVSS 7.5
CVE-2026-9857
MEDIUM
Invoice123 < 1.7.0 - Authorization Bypass
CVSS 4.3
CVE-2026-11990
MEDIUM
KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint
CVSS 5.3
CVE-2026-1946
MEDIUM
GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion
CVSS 4.3
CVE-2026-15026
MEDIUM
Import And Export Users And Customers < 2.4.0 - Information Exposure
CVSS 4.3
CVE-2026-12955
MEDIUM
Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action
CVSS 4.3
CVE-2026-11992
MEDIUM
Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation
CVSS 4.3
CVE-2026-15332
MEDIUM
zhayujie CowAgent Message Endpoint channel.py authorization
CVSS 6.3
CVE-2026-15293
HIGH
WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification
CVSS 8.0
CVE-2026-15291
HIGH
Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
CVSS 7.5
CVE-2026-44918
MEDIUM
Openstack Ironic - Missing Authorization
CVSS 5.5
CVE-2026-11818
MEDIUM
WPCafe <= 3.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API
CVSS 5.4
CVE-2026-15320
MEDIUM
Sipeed PicoClaw pico.go rt.ReloadConfig authorization
CVSS 5.4
CVE-2026-59853
MEDIUM
SiYuan < 3.7.1 Publish Mode - Private Saved Search Disclosure
CVSS 6.5
CVE-2026-46413
MEDIUM
Discourse: Regular users can route multipart uploads into the admin backup store
CVSS 6.5
CVE-2026-33802
MEDIUM
Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command
CVSS 5.5
Details
Vulnerabilities
8,807
Exploit Likelihood
High