The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,154 vulnerabilities with CWE-862
CVE-2026-40623
HIGH
SenseLive X3050 Missing Authorization
CVSS 8.1
CVE-2026-41352
HIGH
OpenClaw < 2026.3.31 - Remote Code Execution via Node Scope Gate Bypass
CVSS 8.8
CVE-2026-41349
HIGH
OpenClaw < 2026.3.28 - Agentic Consent Bypass via config.patch
CVSS 8.8
CVE-2026-41266
HIGH
Flowise: Sensitive Data Leak in public-chatbotConfig
CVSS 7.5
CVE-2026-5464
HIGH
ExactMetrics <= 9.1.2 - Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process
CVSS 7.2
CVE-2026-41679
CRITICAL
Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
CVSS 10.0
CVE-2026-41454
HIGH
WeKan < 8.35 Missing Authorization via Integration REST API
CVSS 8.3
CVE-2026-40937
HIGH
RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks
CVSS 8.3
CVE-2026-1930
MEDIUM
Emailchef <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion
CVSS 4.3
CVE-2026-6235
CRITICAL
Sendmachine for WordPress <= 1.0.20 - Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests
CVSS 9.8
CVE-2026-4128
MEDIUM
TP Restore Categories And Taxonomies <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Taxonomy Deletion via 'tpmcattt_delete_term' AJAX Action
CVSS 4.3
CVE-2026-4119
CRITICAL
Create DB Tables <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Table Creation/Deletion via admin-post.php
CVSS 9.1
CVE-2026-4117
MEDIUM
CalJ <= 1.5 - Authenticated (Subscriber+) Arbitrary Settings Modification via 'save-obtained-key' Action
CVSS 5.3
CVE-2026-6834
MEDIUM
aEnrich|a+HRD - Missing Authorization
CVSS 6.5
CVE-2026-41128
MEDIUM
Craft CMS 5.6.0-5.9.14 save-permissions - Missing Authorization
CVE-2026-40870
HIGH
Decidim's comments API allows access to all commentable resources
CVSS 7.5
CVE-2026-41192
HIGH
FreeScout's client-controlled attachment IDs allow deletion of existing conversation attachments
CVSS 7.1
CVE-2026-40592
MEDIUM
FreeScout's cross-user undo reply allows mailbox peers to recall another agent's outbound reply
CVSS 5.9
CVE-2026-40570
MEDIUM
FreeScout's Missing Authorization in load_customer_info Allows Any Authenticated User to Access Full Customer PII
CVE-2026-6703
MEDIUM
Responsive Blocks <= 2.2.1 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions
CVSS 4.3
CVE-2026-39386
HIGH
Neko has Self-service Privilege Escalation for Authenticated Users
CVSS 8.8
CVE-2026-41298
MEDIUM
OpenClaw < 2026.4.2 - Authorization Bypass in Session Termination Endpoint
CVSS 5.4
CVE-2026-40098
MEDIUM
OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variant
CVSS 5.4
CVE-2026-25058
HIGH
Vexa's unauthenticated internal transcript endpoint exposed by default
CVSS 7.5
CVE-2026-6589
MEDIUM
ComfyUI server.py create_origin_only_middleware cross-site request forgery
CVSS 4.3
Details
Vulnerabilities
8,154
Exploit Likelihood
High