The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,222 vulnerabilities with CWE-862
CVE-2026-0026
HIGH
PermissionManagerServiceImpl - Privilege Escalation
CVSS 7.8
CVE-2026-0024
MEDIUM
Android - Unauthenticated Local Information Disclosure via MediaProvider Content Resolver
CVSS 4.0
CVE-2026-3432
CRITICAL
SimStudio < 0.5.74 - Unauthenticated OAuth Token Theft via credentialAccountUserId and providerId Parameters
CVSS 9.1
CVE-2026-3431
CRITICAL
SimStudio <0.5.74 - Unauthenticated MongoDB Access
CVSS 9.8
CVE-2026-28557
MEDIUM
wpForo Forum 2.4.14 - Privilege Escalation
CVSS 6.5
CVE-2026-28556
MEDIUM
wpForo Forum 2.4.14 - Privilege Escalation
CVSS 5.4
CVE-2026-28555
MEDIUM
wpForo Forum 2.4.14 - Privilege Escalation
CVSS 4.3
CVE-2026-28554
MEDIUM
wpForo Forum 2.4.14 - Privilege Escalation
CVSS 4.3
CVE-2026-28515
HIGH
openDCIM 23.04 - Privilege Escalation
CVSS 8.8
CVE-2026-28424
MEDIUM
Statmatic <5.73.11/6.4.0 - Info Disclosure
CVSS 6.5
CVE-2026-28408
CRITICAL
WeGIA < 3.6.5 - Unauthenticated Improper Authentication via adicionar_tipo_docs_atendido.php
CVSS 9.8
CVE-2026-27836
HIGH
phpmyfaq < 4.0.18 - Unauthenticated Account Creation via WebAuthn Prepare Endpoint
CVSS 7.5
CVE-2026-27792
MEDIUM
Seerr 2.7.0-3.0.9 - Privilege Escalation
CVSS 5.4
CVE-2026-28276
HIGH
Initiative <0.32.2 - Info Disclosure
CVSS 7.5
CVE-2026-28217
MEDIUM
hoppscotch < 2026.2.0 - Authenticated Insecure Direct Object Reference via userCollection GraphQL Query
CVSS 6.5
CVE-2026-27638
HIGH
Actual sync-server < 26.2.1 - Authenticated Missing Authorization in Sync API Endpoints
CVSS 7.1
CVE-2026-27457
MEDIUM
Weblate < 5.16.1 - Unauthorized Addon Information Exposure via REST API
CVSS 4.3
CVE-2026-27151
LOW
Discourse <2025.12.2/2026.1.1/2026.2.0 - Privilege Escalation
CVSS 2.7
CVE-2026-27150
LOW
Discourse <2025.12.2/2026.1.1/2026.2.0 - Info Disclosure
CVSS 3.8
CVE-2026-27021
MEDIUM
Discourse <2025.12.2/2026.1.1/2026.2.0 - Info Disclosure
CVSS 5.3
CVE-2026-26979
LOW
Discourse <2025.12.2 - Privilege Escalation
CVSS 2.7
CVE-2026-26207
MEDIUM
Discourse <2025.12.2/2026.1.1/2026.2.0 - Auth Bypass
CVSS 5.4
CVE-2026-24004
MEDIUM
Fleet <4.80.1 - Unauthenticated Device Unenrollment
CVSS 5.3
CVE-2026-27954
MEDIUM
Live Helper Chat <4.52 - Privilege Escalation
CVSS 6.5
CVE-2026-27946
MEDIUM
ZITADEL <4.11.1/3.4.7 - Auth Bypass
CVSS 6.5
Details
Vulnerabilities
8,222
Exploit Likelihood
High