The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,213 vulnerabilities with CWE-862
CVE-2026-29515
CRITICAL
MiCode FileExplorer - Unauthenticated Authentication Bypass in SwiFTP FTP Server
CVSS 9.8
CVE-2026-1781
MEDIUM
MC4WP: Mailchimp for WordPress <=4.11.1 - Auth Bypass
CVSS 6.5
CVE-2026-31834
HIGH
Umbraco 15.3.1-16.5.0/17.2.1 - Privilege Escalation
CVSS 7.2
CVE-2026-31821
MEDIUM
Sylius <2.0.16/2.1.12/2.2.3 - Auth Bypass
CVSS 5.3
CVE-2026-31800
CRITICAL
Parse Server <9.5.2-alpha.12/8.6.25 - Auth Bypass
CVSS 9.1
CVE-2026-3582
MEDIUM
GitHub Enterprise Server - Incorrect Authorization
CVSS 4.3
CVE-2026-26742
HIGH
PX4 Autopilot 1.12.x-1.15.x - Auth Bypass
CVSS 8.1
CVE-2026-26741
HIGH
PX4 Autopilot 1.12.x-1.15.x - Logic Flaw
CVSS 8.1
CVE-2026-30970
CRITICAL
Coral Server < 1.1.0 - Unauthenticated Resource Exhaustion via Session Creation Endpoint
CVSS 9.1
CVE-2026-30968
CRITICAL
Coral Server < 1.1.0 - Unauthenticated Message Injection or Observation via SSE Endpoint
CVSS 9.8
CVE-2026-30959
MEDIUM
OneUptime < 10.0.21 - Authenticated Authorization Bypass via Resend-Verification-Code Endpoint
CVSS 5.0
CVE-2026-30956
CRITICAL
OneUptime < 10.0.21 - Missing Authorization via Forged is-multi-tenant-query Header
CVSS 9.9
CVE-2026-30920
HIGH
OneUptime < 10.0.19 - Missing Authorization in GitHub App Callback
CVSS 8.6
CVE-2026-30885
MEDIUM
WWBN AVideo <25.0 - Info Disclosure
CVSS 5.3
CVE-2026-27688
MEDIUM
SAP NetWeaver ABAP - Privilege Escalation
CVSS 5.0
CVE-2026-27687
MEDIUM
SAP S/4HANA HCM Portugal - Info Disclosure
CVSS 5.8
CVE-2026-27686
MEDIUM
SAP Business Warehouse - Authenticated Missing Authorization Check in Service API
CVSS 5.9
CVE-2026-24313
MEDIUM
SAP Solution Tools Plug-In - Missing Authorization for System Information Disclosure
CVSS 5.0
CVE-2026-24310
LOW
SAP NetWeaver ABAP - Info Disclosure
CVSS 3.5
CVE-2026-24309
MEDIUM
SAP NetWeaver ABAP - Privilege Escalation
CVSS 6.4
CVE-2026-30926
HIGH
SiYuan <3.5.10 - Privilege Escalation
CVSS 7.1
CVE-2026-28433
MEDIUM
Misskey 10.93.0-2026.3.0 - Auth Bypass
CVSS 4.3
CVE-2026-25045
HIGH
Budibase < 3.32.3 - Missing Authorization in /api/global/users Endpoint
CVSS 8.8
CVE-2026-3638
MEDIUM
Devolutions Server <2025.3.11.0 - Privilege Escalation
CVSS 5.9
CVE-2026-3770
MEDIUM
SourceCodester Computer Laboratory Management System 1.0 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities
8,213
Exploit Likelihood
High