CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,807 vulnerabilities with CWE-862
CVE-2026-31309 CRITICAL
Mysterium Node < 1.36.0 - Unauthenticated Configuration Overwrite and Node Takeover via /tequilapi/config/user Endpoint
CVSS 9.8
CVE-2026-8472 MEDIUM
Missing Authorization in GitLab
CVSS 4.3
CVE-2026-7492 MEDIUM
Missing Authorization in GitLab
CVSS 4.3
CVE-2026-55542 MEDIUM
Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
CVSS 4.3
CVE-2026-59805 MEDIUM
Gumroad < 2026.07.06.2 - Insecure Direct Object Reference in PurchasesController
CVSS 6.5
CVE-2026-14373 HIGH
Nomad Docker driver Linux host namespace bypass
CVSS 7.7
CVE-2026-59262 MEDIUM
AFFiNE - Unauthorized Document Edit History Access via GraphQL histories Field
CVSS 6.5
CVE-2026-60124 MEDIUM
MISP importModule missing authorization allows read-only users to modify events via misp_standard imports
CVE-2026-56250 HIGH
Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions
CVSS 7.5
CVE-2026-15034 MEDIUM
flask-dashboard Flask-MonitoringDashboard cross-site request forgery
CVSS 4.3
CVE-2026-5356 HIGH
LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass
CVSS 7.5
CVE-2026-12153 CRITICAL
WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action
CVSS 9.8
CVE-2026-12097 MEDIUM
User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification
CVSS 5.3
CVE-2026-55433 MEDIUM
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
CVSS 5.4
CVE-2026-55432 MEDIUM
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
CVSS 5.4
CVE-2026-59704 HIGH
Cap - Missing Access Control in Video AI Metadata Endpoint
CVSS 7.1
CVE-2026-58473 CRITICAL
Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings
CVSS 9.1
CVE-2026-55417 MEDIUM
Chevereto private profile setting leaks username on /json endpoint
CVE-2026-53730 HIGH
DataEase: Unauthorized Access to Engine Database via previewSql Endpoint
CVE-2026-50007 HIGH
Actual: Shared users can perform owner-only file management actions
CVE-2026-59708 HIGH
Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint
CVSS 7.5
CVE-2026-59709 MEDIUM
Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission Check
CVSS 4.3
CVE-2026-11340 HIGH
Authorization Bypass in HAVELSAN's Open Source Project Liman MYS
CVSS 8.3
CVE-2026-8377 HIGH
Improper Authorization in Armiya Technologies' Access Control System
CVSS 8.2
CVE-2026-34048 CRITICAL
Coolify < 4.0.0-beta.471 - Low-Privileged Terminal Command Execution
CVSS 9.9
Details
Vulnerabilities 8,807
Exploit Likelihood High