The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,211 vulnerabilities with CWE-862
CVE-2026-33866
MEDIUM
Authorization Bypass in MLflow AJAX Endpoint
CVSS 4.3
CVE-2026-34903
MEDIUM
WordPress Ocean Extra plugin <= 2.5.3 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-34899
MEDIUM
WordPress LTL Freight Quotes – Worldwide Express Edition plugin <= 5.2.1 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-35448
LOW
WWBN AVideo Provides Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php
CVSS 3.7
CVE-2026-35182
HIGH
Brave CMS < 2.0.6 - Super Admin Privilege Escalation
CVSS 8.8
CVE-2026-35179
MEDIUM
WWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php
CVSS 5.3
CVE-2026-35175
MEDIUM
Ajenti <2.2.15 Custom Package Installation - Authorization Bypass
CVSS 6.5
CVE-2026-34976
CRITICAL
Dgraph Affected by Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
CVSS 10.0
CVE-2026-3524
HIGH
Authorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission Check
CVSS 8.8
CVE-2026-5624
MEDIUM
ProjectSend upload.php cross-site request forgery
CVSS 4.3
CVE-2026-5574
MEDIUM
Technostrobe HI-LED-WR120-G2 FsBrowseClean deletefile authorization
CVSS 6.5
CVE-2026-5572
MEDIUM
Technostrobe HI-LED-WR120-G2 cross-site request forgery
CVSS 4.3
CVE-2026-3445
HIGH
ProfilePress <= 4.16.11 - Authenticated Membership Payment Bypass via change_plan_sub_id
CVSS 7.1
CVE-2026-2826
MEDIUM
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload
CVSS 4.3
CVE-2026-3571
MEDIUM
Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization to Unauthenticated Registration Form Status Modification
CVSS 6.5
CVE-2026-34766
LOW
Electron: USB device selection not validated against filtered device list
CVSS 3.3
CVE-2026-27833
HIGH
Piwigo: Unauthenticated Information Disclosure via pwg.history.search API
CVSS 7.5
CVE-2026-35561
HIGH
Insufficient authentication security controls in browser-based authentication components in Amazon Athena ODBC driver
CVSS 7.4
CVE-2026-25742
MEDIUM
Zulip: Anonymous File Access After Disabling Spectator Access
CVSS 5.3
CVE-2026-22663
HIGH
prompts.chat Authorization Bypass Information Disclosure
CVSS 7.5
CVE-2026-34759
HIGH
OneUptime: Unauthenticated notification API endpoints - financial abuse via phone number purchase, service disruption, and SMTP credential exposure
CVSS 8.1
CVE-2026-33950
CRITICAL
signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity
CVSS 9.4
CVE-2026-20155
HIGH
Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability
CVSS 8.0
CVE-2026-5175
MEDIUM
Devolutions Server 2026.1.6-2026.1.11 - Auth Bypass
CVSS 5.0
CVE-2026-4925
MEDIUM
Devolutions Server 2026.1.6-2026.1.11 - Auth Bypass
CVSS 5.0
Details
Vulnerabilities
8,211
Exploit Likelihood
High