CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,808 vulnerabilities with CWE-862
CVE-2026-56767 HIGH
Maxun < 0.0.42 - Cross-Tenant IDOR in Storage and Webhook API Handlers
CVSS 8.8
CVE-2026-54029 MEDIUM
LibreChat < 0.8.4-rc1 - Unauthorized Message Deletion
CVSS 5.3
CVE-2026-54027 MEDIUM
LibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fix for File Upload Authorization
CVSS 6.5
CVE-2026-48941 MEDIUM
Joomla Extension - getk2.com - Unauthenticated folder delete in K2 extension for Joomla < 2.26
CVSS 6.5
CVE-2026-57619 MEDIUM
WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2026-57429 MEDIUM
WordPress Slim SEO plugin <= 4.6.2 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-56023 MEDIUM
WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.6.2 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-54844 HIGH
WordPress CheckView Automated Testing plugin <= 2.1.0 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-54842 HIGH
WordPress Royal MCP plugin <= 1.4.25 - Broken Access Control vulnerability
CVSS 8.1
CVE-2026-54830 HIGH
WordPress Five Star Restaurant Reservations plugin <= 2.7.19 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-54828 HIGH
WordPress Motors plugin <= 1.4.109 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-27366 HIGH
WordPress MainWP Child plugin <= 6.1.1 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-3176 LOW
Missing Authorization in GitLab
CVSS 3.1
CVE-2026-2238 MEDIUM
Missing Authorization in GitLab
CVSS 5.3
CVE-2026-55762 HIGH
Rocket.Chat fingerprint API - Authenticated Workspace Deregistration
CVSS 8.1
CVE-2026-52812 HIGH
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-52799 HIGH
Gogs: Missing Authorization in Attachment Download
CVSS 7.5
CVE-2026-45677 HIGH
Rocket.Chat SAML Logout - Unauthenticated Session Denial of Service
CVE-2026-27708 HIGH
FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access
CVE-2026-57307 MEDIUM
Jenkins Zowe zDevOps Plugin - Missing Authorization
CVSS 4.2
CVE-2026-57304 MEDIUM
Jenkins Assembla Plugin < 1.4 - Missing Authorization
CVSS 5.4
CVE-2026-57300 MEDIUM
Jenkins Mcp Server Plugin - Missing Authorization
CVSS 4.3
CVE-2026-57299 MEDIUM
Jenkins Contrast Continuous Application Security Plugin < 3.11 - Unauthenticated Metadata Enumeration
CVSS 4.3
CVE-2026-57297 MEDIUM
Jenkins Contrast Plugin < 3.11 SSRF via Missing Permission Check
CVSS 4.3
CVE-2026-57294 MEDIUM
Jenkins EC2 Fleet Plugin - Missing Authorization
CVSS 5.4
Details
Vulnerabilities 8,808
Exploit Likelihood High