The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,143 vulnerabilities with CWE-862
CVE-2026-42412
MEDIUM
WordPress WP User Frontend plugin <= 4.3.1 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-42377
HIGH
WordPress SureForms Pro plugin <= 2.8.0 - Broken Access Control vulnerability
CVSS 7.3
CVE-2026-41394
HIGH
OpenClaw < 2026.3.31 - Unauthorized Operator Scope Access in Unauthenticated Plugin-Auth Routes
CVSS 8.2
CVE-2026-41382
MEDIUM
OpenClaw < 2026.3.31 - Discord Voice Ingress Authorization Bypass via Channel and Role Validation Gaps
CVSS 5.4
CVE-2026-41378
HIGH
OpenClaw < 2026.3.31 - Privilege Escalation to Remote Code Execution via Unrestricted node.event Agent Dispatch
CVSS 8.8
CVE-2026-6706
MEDIUM
Devolutions Server <=2026.1.14.0 - Auth Bypass
CVSS 6.5
CVE-2026-5944
HIGH
Cisco Intersight Device Connector for Nutanix Prism Central Unauthenticated API Access
CVSS 8.2
CVE-2026-40976
CRITICAL
Spring Boot 4.0.0-4.0.5 - Auth Bypass
CVSS 9.1
CVE-2026-41464
MEDIUM
ProjeQtor < 12.4.4 Missing Authorization via objectDetail.php
CVSS 6.5
CVE-2026-7108
MEDIUM
code-projects Invoice System in Laravel cross-site request forgery
CVSS 4.3
CVE-2026-41477
HIGH
Deskflow: Local privilege escalation via unauthenticated IPC
CVSS 7.8
CVE-2026-3569
MEDIUM
Liaison Site Prober <= 1.2.1 - Missing Authorization to Unauthenticated Information Exposure in '/logs' REST API Endpoint
CVSS 5.3
CVE-2026-5347
MEDIUM
WP Books Gallery <= 4.8.0 - Missing Authorization to Unauthenticated Settings Update via 'permalink_structure' Parameter
CVSS 5.3
CVE-2026-6393
MEDIUM
BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage
CVSS 4.3
CVE-2026-5488
MEDIUM
ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token'
CVSS 5.3
CVE-2026-33318
HIGH
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
CVSS 8.8
CVE-2026-40623
HIGH
SenseLive X3050 Missing Authorization
CVSS 8.1
CVE-2026-41352
HIGH
OpenClaw < 2026.3.31 - Remote Code Execution via Node Scope Gate Bypass
CVSS 8.8
CVE-2026-41349
HIGH
OpenClaw < 2026.3.28 - Agentic Consent Bypass via config.patch
CVSS 8.8
CVE-2026-41266
HIGH
Flowise: Sensitive Data Leak in public-chatbotConfig
CVSS 7.5
CVE-2026-5464
HIGH
ExactMetrics <= 9.1.2 - Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process
CVSS 7.2
CVE-2026-41679
CRITICAL
Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
CVSS 10.0
CVE-2026-41454
HIGH
WeKan < 8.35 Missing Authorization via Integration REST API
CVSS 8.3
CVE-2026-40937
HIGH
RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks
CVSS 8.3
CVE-2026-1930
MEDIUM
Emailchef <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion
CVSS 4.3
Details
Vulnerabilities
8,143
Exploit Likelihood
High