CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,807 vulnerabilities with CWE-862
CVE-2026-54695 HIGH
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
CVSS 7.5
CVE-2026-54005 HIGH
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
CVE-2026-54004 MEDIUM
Kirby: Access to files of top-level drafts is not protected by permissions
CVE-2026-49274 MEDIUM
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
CVE-2026-59227 MEDIUM
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVSS 4.3
CVE-2026-59226 LOW
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVSS 3.1
CVE-2026-59225 MEDIUM
Open WebUI: Arena task endpoints can bypass underlying model access controls
CVSS 5.4
CVE-2026-59217 MEDIUM
Open WebUI < 0.10.0 - Knowledge Base Write-Access Bypass
CVSS 4.3
CVE-2026-59216 HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
CVSS 7.7
CVE-2026-12593 HIGH
Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystem
CVE-2026-9240 MEDIUM
Colissimo for WooCommerce <= 2.9.0 - Subscriber Order Shipment Modification
CVSS 4.3
CVE-2026-9237 MEDIUM
Employee, Leave And Recruitment Management System < 1.2.2 - Authorization Bypass
CVSS 4.3
CVE-2026-9235 MEDIUM
DHL eCommerce (Benelux) for WooCommerce <= 2.2.3 - Subscriber Shipping Label Changes
CVSS 4.3
CVE-2026-9028 MEDIUM
CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Unauthenticated Arbitrary Order Cancellation via 'order_number' Parameter
CVSS 5.3
CVE-2026-9021 MEDIUM
Easy Invoice <= 2.1.19 - Unauthenticated Quote Approval and Invoice Creation
CVSS 5.3
CVE-2026-4298 MEDIUM
DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
CVSS 4.3
CVE-2026-12428 MEDIUM
Blocks for ACF Fields <= 1.6.2 - Missing Authorization to Authenticated (Author+) Arbitrary ACF Field Value Disclosure via 'id' Parameter
CVSS 6.5
CVE-2026-8996 MEDIUM
Backup And Staging BY WP Time Capsule < 1.22.26 - Information Exposure
CVSS 6.5
CVE-2026-8848 HIGH
Popup Maker < 1.22.0 - Remote Code Execution
CVSS 7.2
CVE-2026-7558 MEDIUM
Token of Trust Age Verification <= 4.0.2 - Unauthenticated Donation Data Exposure
CVSS 5.3
CVE-2026-14245 CRITICAL
miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account Takeover via 'username_b' Parameter
CVSS 9.8
CVE-2026-12406 MEDIUM
User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter
CVSS 5.3
CVE-2026-11359 MEDIUM
Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation
CVSS 4.3
CVE-2026-48492 MEDIUM
Snipe-IT's selectlist visibility is too permissive
CVSS 6.5
CVE-2026-35552 HIGH
CAXperts UPVWebServices 2.4.2212.603-2.7.6 & UDiTH Portal 2026.0.0-2026.2.0 Authenticated License Deactivation via API
CVSS 8.1
Details
Vulnerabilities 8,807
Exploit Likelihood High