The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,133 vulnerabilities with CWE-862
CVE-2026-42851
HIGH
@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCE
CVSS 7.8
CVE-2026-50244
MEDIUM
Naxclow IoT Platform Missing Authorization
CVSS 5.3
CVE-2026-50108
HIGH
Naxclow IoT Platform Missing Authorization
CVSS 7.5
CVE-2026-10715
MEDIUM
Camaleon CMS 2.9.2 - Improper authorization in draft autosave endpoint
CVE-2026-6689
MEDIUM
Mattermost Team Creation - Invite Settings Authorization Bypass
CVSS 4.3
CVE-2026-50084
CRITICAL
Aqara API cross-account access
CVSS 9.6
CVE-2026-50026
MEDIUM
Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpoints
CVE-2026-44975
MEDIUM
Frappe: Missing authorization on reset form tours
CVE-2026-7368
HIGH
Yarbo Android/iOS Mobile Application and Cloud Infrastructure Missing Authorization
CVSS 8.1
CVE-2026-47197
HIGH
Quest Bot: Discord moderation role hierarchy bypass in ban, kick, mute, unmute, warn, and nickname commands
CVE-2026-53818
MEDIUM
OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback
CVSS 6.6
CVE-2026-53816
HIGH
OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node
CVSS 7.2
CVE-2026-53815
MEDIUM
OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions
CVSS 6.5
CVE-2026-47163
HIGH
Quest Bot: Unprivileged users can create and remove AutoMod rules.
CVE-2026-4764
CRITICAL
Privilege Escalation in Dialogflow CX via Playbook Import
CVE-2026-46645
MEDIUM
SQLAdmin: Authorization Bypass on `ajax_lookup`
CVSS 4.3
CVE-2026-53634
MEDIUM
Sharp: Missing Authorization Check in Quick Creation Command Endpoints
CVSS 4.3
CVE-2026-0272
MEDIUM
Palo Alto Networks Cloud Ngfw - Privilege Escalation
CVE-2026-49822
HIGH
Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
CVSS 7.7
CVE-2026-49821
HIGH
Fission < 1.24.0 Package Builder - Command Execution via Environment Reference
CVSS 7.7
CVE-2026-46614
CRITICAL
Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
CVSS 9.8
CVE-2026-46558
HIGH
Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces
CVSS 8.3
CVE-2026-45552
CRITICAL
Roxy-WI <= 8.2.6.4 - Cross-Tenant Install Authorization Bypass
CVSS 9.9
CVE-2026-45550
CRITICAL
Roxy-WI: IDOR on PUT /smon/check — any user can rewrite any tenant's monitoring URL/IP/body
CVSS 9.1
CVE-2026-45549
HIGH
Roxy-WI <= 8.2.6.4 - smon-agent Action Authorization Bypass
CVSS 8.5
Details
Vulnerabilities
8,133
Exploit Likelihood
High