CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,133 vulnerabilities with CWE-862
CVE-2026-42851 HIGH
@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCE
CVSS 7.8
CVE-2026-50244 MEDIUM
Naxclow IoT Platform Missing Authorization
CVSS 5.3
CVE-2026-50108 HIGH
Naxclow IoT Platform Missing Authorization
CVSS 7.5
CVE-2026-10715 MEDIUM
Camaleon CMS 2.9.2 - Improper authorization in draft autosave endpoint
CVE-2026-6689 MEDIUM
Mattermost Team Creation - Invite Settings Authorization Bypass
CVSS 4.3
CVE-2026-50084 CRITICAL
Aqara API cross-account access
CVSS 9.6
CVE-2026-50026 MEDIUM
Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpoints
CVE-2026-44975 MEDIUM
Frappe: Missing authorization on reset form tours
CVE-2026-7368 HIGH
Yarbo Android/iOS Mobile Application and Cloud Infrastructure Missing Authorization
CVSS 8.1
CVE-2026-47197 HIGH
Quest Bot: Discord moderation role hierarchy bypass in ban, kick, mute, unmute, warn, and nickname commands
CVE-2026-53818 MEDIUM
OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback
CVSS 6.6
CVE-2026-53816 HIGH
OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node
CVSS 7.2
CVE-2026-53815 MEDIUM
OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions
CVSS 6.5
CVE-2026-47163 HIGH
Quest Bot: Unprivileged users can create and remove AutoMod rules.
CVE-2026-4764 CRITICAL
Privilege Escalation in Dialogflow CX via Playbook Import
CVE-2026-46645 MEDIUM
SQLAdmin: Authorization Bypass on `ajax_lookup`
CVSS 4.3
CVE-2026-53634 MEDIUM
Sharp: Missing Authorization Check in Quick Creation Command Endpoints
CVSS 4.3
CVE-2026-0272 MEDIUM
Palo Alto Networks Cloud Ngfw - Privilege Escalation
CVE-2026-49822 HIGH
Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
CVSS 7.7
CVE-2026-49821 HIGH
Fission < 1.24.0 Package Builder - Command Execution via Environment Reference
CVSS 7.7
CVE-2026-46614 CRITICAL
Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
CVSS 9.8
CVE-2026-46558 HIGH
Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces
CVSS 8.3
CVE-2026-45552 CRITICAL
Roxy-WI <= 8.2.6.4 - Cross-Tenant Install Authorization Bypass
CVSS 9.9
CVE-2026-45550 CRITICAL
Roxy-WI: IDOR on PUT /smon/check — any user can rewrite any tenant's monitoring URL/IP/body
CVSS 9.1
CVE-2026-45549 HIGH
Roxy-WI <= 8.2.6.4 - smon-agent Action Authorization Bypass
CVSS 8.5
Details
Vulnerabilities 8,133
Exploit Likelihood High