The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,807 vulnerabilities with CWE-862
CVE-2026-31309
CRITICAL
Mysterium Node < 1.36.0 - Unauthenticated Configuration Overwrite and Node Takeover via /tequilapi/config/user Endpoint
CVSS 9.8
CVE-2026-8472
MEDIUM
Missing Authorization in GitLab
CVSS 4.3
CVE-2026-7492
MEDIUM
Missing Authorization in GitLab
CVSS 4.3
CVE-2026-55542
MEDIUM
Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
CVSS 4.3
CVE-2026-59805
MEDIUM
Gumroad < 2026.07.06.2 - Insecure Direct Object Reference in PurchasesController
CVSS 6.5
CVE-2026-14373
HIGH
Nomad Docker driver Linux host namespace bypass
CVSS 7.7
CVE-2026-59262
MEDIUM
AFFiNE - Unauthorized Document Edit History Access via GraphQL histories Field
CVSS 6.5
CVE-2026-60124
MEDIUM
MISP importModule missing authorization allows read-only users to modify events via misp_standard imports
CVE-2026-56250
HIGH
Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions
CVSS 7.5
CVE-2026-15034
MEDIUM
flask-dashboard Flask-MonitoringDashboard cross-site request forgery
CVSS 4.3
CVE-2026-5356
HIGH
LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass
CVSS 7.5
CVE-2026-12153
CRITICAL
WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action
CVSS 9.8
CVE-2026-12097
MEDIUM
User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification
CVSS 5.3
CVE-2026-55433
MEDIUM
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
CVSS 5.4
CVE-2026-55432
MEDIUM
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
CVSS 5.4
CVE-2026-59704
HIGH
Cap - Missing Access Control in Video AI Metadata Endpoint
CVSS 7.1
CVE-2026-58473
CRITICAL
Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings
CVSS 9.1
CVE-2026-55417
MEDIUM
Chevereto private profile setting leaks username on /json endpoint
CVE-2026-53730
HIGH
DataEase: Unauthorized Access to Engine Database via previewSql Endpoint
CVE-2026-50007
HIGH
Actual: Shared users can perform owner-only file management actions
CVE-2026-59708
HIGH
Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint
CVSS 7.5
CVE-2026-59709
MEDIUM
Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission Check
CVSS 4.3
CVE-2026-11340
HIGH
Authorization Bypass in HAVELSAN's Open Source Project Liman MYS
CVSS 8.3
CVE-2026-8377
HIGH
Improper Authorization in Armiya Technologies' Access Control System
CVSS 8.2
CVE-2026-34048
CRITICAL
Coolify < 4.0.0-beta.471 - Low-Privileged Terminal Command Execution
CVSS 9.9
Details
Vulnerabilities
8,807
Exploit Likelihood
High