The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,808 vulnerabilities with CWE-862
CVE-2026-12113
MEDIUM
Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure
CVSS 4.3
CVE-2026-14156
MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via StorageAccessAPI
CVSS 6.5
CVE-2026-58448
MEDIUM
yudao-cloud < 2026.06 - BPM Module Broken Access Control via process-instance API
CVSS 6.5
CVE-2026-9132
MEDIUM
GitHub Enterprise Server < 3.21 - Private Repository Source Disclosure
CVSS 6.5
CVE-2026-58377
HIGH
JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys
CVSS 8.1
CVE-2026-58373
MEDIUM
CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence
CVSS 4.3
CVE-2026-58176
MEDIUM
RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints
CVSS 6.5
CVE-2026-58168
HIGH
DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin Users
CVSS 8.8
CVE-2026-58167
MEDIUM
Nightingale < 9.0.0-beta.2 - Datasource Credential Disclosure to Low-Privilege Users
CVSS 6.5
CVE-2026-58165
HIGH
OpenZiti - Privilege Escalation to Admin via Unauthorized Enrollment Creation
CVSS 8.8
CVE-2026-54475
HIGH
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover
CVSS 7.5
CVE-2026-12349
MEDIUM
Premium Addons for KingComposer <= 1.1.1 - Unauthenticated Sidebar Modification
CVSS 5.3
CVE-2026-57498
CRITICAL
Coolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and destination_uuid — Deploy to Other Teams' Servers
CVSS 9.6
CVE-2026-57954
MEDIUM
Elide 7.1.17 - Permission Bypass in Sort Expression Validation
CVSS 4.3
CVE-2026-57952
MEDIUM
Mythic < 3.4.0.60 - Unauthorized C2 Profile Configuration Access via Unverified Payload UUID
CVSS 5.3
CVE-2026-57949
MEDIUM
ruoyi-vue-pro - Missing Authorization in CRM Follow-up Record GET Endpoint
CVSS 6.5
CVE-2026-57946
LOW
Invidious - Private Playlist Disclosure via Unauthenticated RSS Feed Endpoint
CVSS 3.7
CVE-2026-57340
MEDIUM
WordPress Japanized For WooCommerce plugin <= 2.9.12 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57339
MEDIUM
WordPress Business Directory plugin <= 6.4.23 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57335
MEDIUM
WordPress Ads by WPQuads plugin <= 3.0.3 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57334
MEDIUM
WordPress WP User Frontend plugin <= 4.3.7 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57332
HIGH
WordPress Wallet System for WooCommerce plugin <= 2.7.6 - Broken Access Control vulnerability
CVSS 7.1
CVE-2026-57327
MEDIUM
WordPress MainWP plugin <= 6.1.1 - Broken Access Control vulnerability
CVSS 6.3
CVE-2026-13537
MEDIUM
CodeAstro Human Resource Management System cross-site request forgery
CVSS 4.3
CVE-2026-13484
MEDIUM
MLflow Experiment-scoped Label Schema CRUD API authorization
CVSS 5.0
Details
Vulnerabilities
8,808
Exploit Likelihood
High