CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,808 vulnerabilities with CWE-862
CVE-2026-12113 MEDIUM
Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure
CVSS 4.3
CVE-2026-14156 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via StorageAccessAPI
CVSS 6.5
CVE-2026-58448 MEDIUM
yudao-cloud < 2026.06 - BPM Module Broken Access Control via process-instance API
CVSS 6.5
CVE-2026-9132 MEDIUM
GitHub Enterprise Server < 3.21 - Private Repository Source Disclosure
CVSS 6.5
CVE-2026-58377 HIGH
JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys
CVSS 8.1
CVE-2026-58373 MEDIUM
CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence
CVSS 4.3
CVE-2026-58176 MEDIUM
RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints
CVSS 6.5
CVE-2026-58168 HIGH
DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin Users
CVSS 8.8
CVE-2026-58167 MEDIUM
Nightingale < 9.0.0-beta.2 - Datasource Credential Disclosure to Low-Privilege Users
CVSS 6.5
CVE-2026-58165 HIGH
OpenZiti - Privilege Escalation to Admin via Unauthorized Enrollment Creation
CVSS 8.8
CVE-2026-54475 HIGH
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover
CVSS 7.5
CVE-2026-12349 MEDIUM
Premium Addons for KingComposer <= 1.1.1 - Unauthenticated Sidebar Modification
CVSS 5.3
CVE-2026-57498 CRITICAL
Coolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and destination_uuid — Deploy to Other Teams' Servers
CVSS 9.6
CVE-2026-57954 MEDIUM
Elide 7.1.17 - Permission Bypass in Sort Expression Validation
CVSS 4.3
CVE-2026-57952 MEDIUM
Mythic < 3.4.0.60 - Unauthorized C2 Profile Configuration Access via Unverified Payload UUID
CVSS 5.3
CVE-2026-57949 MEDIUM
ruoyi-vue-pro - Missing Authorization in CRM Follow-up Record GET Endpoint
CVSS 6.5
CVE-2026-57946 LOW
Invidious - Private Playlist Disclosure via Unauthenticated RSS Feed Endpoint
CVSS 3.7
CVE-2026-57340 MEDIUM
WordPress Japanized For WooCommerce plugin <= 2.9.12 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57339 MEDIUM
WordPress Business Directory plugin <= 6.4.23 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57335 MEDIUM
WordPress Ads by WPQuads plugin <= 3.0.3 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57334 MEDIUM
WordPress WP User Frontend plugin <= 4.3.7 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57332 HIGH
WordPress Wallet System for WooCommerce plugin <= 2.7.6 - Broken Access Control vulnerability
CVSS 7.1
CVE-2026-57327 MEDIUM
WordPress MainWP plugin <= 6.1.1 - Broken Access Control vulnerability
CVSS 6.3
CVE-2026-13537 MEDIUM
CodeAstro Human Resource Management System cross-site request forgery
CVSS 4.3
CVE-2026-13484 MEDIUM
MLflow Experiment-scoped Label Schema CRUD API authorization
CVSS 5.0
Details
Vulnerabilities 8,808
Exploit Likelihood High