The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,230 vulnerabilities with CWE-862
CVE-2026-0998
MEDIUM
Mattermost 11.1.x-11.1.2 - Auth Bypass
CVSS 4.3
CVE-2026-0929
MEDIUM
RegistrationMagic <6.0.7.2 - Privilege Escalation
CVSS 4.3
CVE-2026-26368
HIGH
eNet SMART HOME 2.2.1/2.3.1 - Privilege Escalation
CVSS 8.8
CVE-2026-26367
HIGH
eNet SMART HOME 2.2.1/2.3.1 - Privilege Escalation
CVSS 8.1
CVE-2026-2312
MEDIUM
Media Library Folders <8.3.6 - Privilege Escalation
CVSS 4.3
CVE-2026-1254
MEDIUM
Modula Image Gallery - Photo Grid & Video Gallery <2.13.6 - Auth By...
CVSS 4.3
CVE-2026-2022
MEDIUM
WordPress Smart Forms <2.6.99 - Info Disclosure
CVSS 4.3
CVE-2026-1944
MEDIUM
CallbackKiller service widget <1.2 - Info Disclosure
CVSS 5.3
CVE-2026-1303
MEDIUM
MailChimp Campaigns <3.2.4 - Privilege Escalation
CVSS 5.3
CVE-2026-0727
MEDIUM
Accordion Slider <1.4.5 - Auth Bypass
CVSS 5.4
CVE-2026-1932
MEDIUM
Bookr plugin <1.0.2 - Info Disclosure
CVSS 5.3
CVE-2026-0692
HIGH
BlueSnap Payment Gateway <3.3.0 - Auth Bypass
CVSS 7.5
CVE-2026-26268
HIGH
Cursor < 2.5 - Sandbox Escape and Remote Code Execution via .git Configuration Injection
CVSS 8.0
CVE-2026-25531
MEDIUM
kanboard < 1.2.50 - Authenticated Missing Authorization in Task Duplication Endpoint
CVSS 4.3
CVE-2026-25768
MEDIUM
LavinMQ < 2.6.6 - Authenticated Unauthorized Metadata Access
CVSS 6.5
CVE-2026-1104
HIGH
FastDup <= 2.7.1 - Authenticated Backup Creation/Download via REST API
CVSS 8.8
CVE-2026-1671
MEDIUM
WordPress Activity Log <1.2.8 - Info Disclosure
CVSS 6.5
CVE-2026-1537
MEDIUM
LatePoint - Calendar Booking Plugin - Info Disclosure
CVSS 5.3
CVE-2026-20626
HIGH
macOS <15.7.4-iPadOS <26.3-visionOS <26.3 - Privilege Escalation
CVSS 7.8
CVE-2026-25633
MEDIUM
Statamic CMS < 5.73.6 - Missing Authorization for Asset Download
CVSS 4.3
CVE-2026-1833
MEDIUM
WaMate Confirm - Order Confirmation <2.0.1 - Auth Bypass
CVSS 5.3
CVE-2026-1786
MEDIUM
Twitter posts to Blog plugin <1.11.25 - Info Disclosure
CVSS 6.5
CVE-2026-1748
MEDIUM
Invoct - PDF Invoices & Billing for WooCommerce <1.7 - Info Disclosure
CVSS 4.3
CVE-2026-25609
MEDIUM
MongoDB 7.0.0-7.0.28 - Missing Authorization via Profile Command Filter Alteration
CVSS 5.4
CVE-2026-21743
HIGH
Fortinet FortiAuthenticator 6.3.0-6.6.6 - Missing Authorization for Local User Modification via File Upload
CVSS 7.2
Details
Vulnerabilities
8,230
Exploit Likelihood
High