CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

7,700 vulnerabilities with CWE-862
CVE-2026-40742 MEDIUM
WordPress Nelio AB Testing plugin <= 8.2.8 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-40740 MEDIUM
WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-40730 MEDIUM
WordPress ThemeGrill Demo Importer plugin <= 2.0.0.6 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-40729 MEDIUM
WordPress 3D viewer – Embed 3D Models plugin <= 1.8.5 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-40728 MEDIUM
WordPress Magazine Blocks plugin <= 1.8.3 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-27769 LOW
Connected Workspaces: Malicious remote server can manipulate arbitrary user's status
CVSS 2.7
CVE-2026-3649 MEDIUM
Katalogportal-pdf-sync Widget <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure via 'katalogportal_shortcodePrinter' AJAX Action
CVSS 5.3
CVE-2026-3642 MEDIUM
e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX
CVSS 5.3
CVE-2026-4812 MEDIUM
Advanced Custom Fields (ACF®) <= 6.7.0 - Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters
CVSS 5.3
CVE-2026-1314 MEDIUM
3D FlipBook < 1.16.17 - Information Exposure
CVSS 5.3
CVE-2026-35033 CRITICAL
Jellyfin: Potential SSRF + Arbitrary file read via stream argument injection
CVSS 9.1
CVE-2026-4109 MEDIUM
Eventin < 4.1.8 - Information Exposure
CVSS 4.3
CVE-2026-4365 CRITICAL
LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion
CVSS 9.1
CVE-2026-34261 MEDIUM
Missing Authorization check in SAP Business Analytics and SAP Content Management
CVSS 6.5
CVE-2026-34256 HIGH
Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)
CVSS 7.1
CVE-2026-27679 MEDIUM
Missing Authorization check in SAP S/4HANA Frontend OData Service (Manage Reference Structures)
CVSS 6.5
CVE-2026-27678 MEDIUM
Missing Authorization check in SAP S/4HANA Backend OData Service (Manage Reference Structures)
CVSS 6.5
CVE-2026-27677 MEDIUM
Missing Authorization check in SAP S/4HANA OData Service (Manage Reference Equipment)
CVSS 6.5
CVE-2026-27676 MEDIUM
Missing Authorization check in SAP S/4HANA OData Service (Manage Technical Object Structures)
CVSS 4.3
CVE-2026-27673 MEDIUM
Missing Authorization Check in SAP S/4HANA (Private Cloud and On-Premise)
CVSS 4.9
CVE-2026-27672 MEDIUM
Missing Authorization check in Material Master Application
CVSS 4.3
CVE-2026-32270 LOW
Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments
CVE-2026-6109 MEDIUM
FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery
CVSS 4.3
CVE-2026-3358 MEDIUM
Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment
CVSS 5.4
CVE-2026-40189 CRITICAL
goshs has a file-based ACL authorization bypass in goshs state-changing routes
CVSS 9.8
Details
Vulnerabilities 7,700
Exploit Likelihood High