CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,230 vulnerabilities with CWE-862
CVE-2026-0998 MEDIUM
Mattermost 11.1.x-11.1.2 - Auth Bypass
CVSS 4.3
CVE-2026-0929 MEDIUM
RegistrationMagic <6.0.7.2 - Privilege Escalation
CVSS 4.3
CVE-2026-26368 HIGH
eNet SMART HOME 2.2.1/2.3.1 - Privilege Escalation
CVSS 8.8
CVE-2026-26367 HIGH
eNet SMART HOME 2.2.1/2.3.1 - Privilege Escalation
CVSS 8.1
CVE-2026-2312 MEDIUM
Media Library Folders <8.3.6 - Privilege Escalation
CVSS 4.3
CVE-2026-1254 MEDIUM
Modula Image Gallery - Photo Grid & Video Gallery <2.13.6 - Auth By...
CVSS 4.3
CVE-2026-2022 MEDIUM
WordPress Smart Forms <2.6.99 - Info Disclosure
CVSS 4.3
CVE-2026-1944 MEDIUM
CallbackKiller service widget <1.2 - Info Disclosure
CVSS 5.3
CVE-2026-1303 MEDIUM
MailChimp Campaigns <3.2.4 - Privilege Escalation
CVSS 5.3
CVE-2026-0727 MEDIUM
Accordion Slider <1.4.5 - Auth Bypass
CVSS 5.4
CVE-2026-1932 MEDIUM
Bookr plugin <1.0.2 - Info Disclosure
CVSS 5.3
CVE-2026-0692 HIGH
BlueSnap Payment Gateway <3.3.0 - Auth Bypass
CVSS 7.5
CVE-2026-26268 HIGH
Cursor < 2.5 - Sandbox Escape and Remote Code Execution via .git Configuration Injection
CVSS 8.0
CVE-2026-25531 MEDIUM
kanboard < 1.2.50 - Authenticated Missing Authorization in Task Duplication Endpoint
CVSS 4.3
CVE-2026-25768 MEDIUM
LavinMQ < 2.6.6 - Authenticated Unauthorized Metadata Access
CVSS 6.5
CVE-2026-1104 HIGH
FastDup <= 2.7.1 - Authenticated Backup Creation/Download via REST API
CVSS 8.8
CVE-2026-1671 MEDIUM
WordPress Activity Log <1.2.8 - Info Disclosure
CVSS 6.5
CVE-2026-1537 MEDIUM
LatePoint - Calendar Booking Plugin - Info Disclosure
CVSS 5.3
CVE-2026-20626 HIGH
macOS <15.7.4-iPadOS <26.3-visionOS <26.3 - Privilege Escalation
CVSS 7.8
CVE-2026-25633 MEDIUM
Statamic CMS < 5.73.6 - Missing Authorization for Asset Download
CVSS 4.3
CVE-2026-1833 MEDIUM
WaMate Confirm - Order Confirmation <2.0.1 - Auth Bypass
CVSS 5.3
CVE-2026-1786 MEDIUM
Twitter posts to Blog plugin <1.11.25 - Info Disclosure
CVSS 6.5
CVE-2026-1748 MEDIUM
Invoct - PDF Invoices & Billing for WooCommerce <1.7 - Info Disclosure
CVSS 4.3
CVE-2026-25609 MEDIUM
MongoDB 7.0.0-7.0.28 - Missing Authorization via Profile Command Filter Alteration
CVSS 5.4
CVE-2026-21743 HIGH
Fortinet FortiAuthenticator 6.3.0-6.6.6 - Missing Authorization for Local User Modification via File Upload
CVSS 7.2
Details
Vulnerabilities 8,230
Exploit Likelihood High