The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
7,700 vulnerabilities with CWE-862
CVE-2026-40185
HIGH
Missing Authorization on Immich Trip Photo Routes in TREK
CVSS 7.1
CVE-2026-33708
MEDIUM
Chamilo LMS has REST API PII Exposure via get_user_info_from_username
CVSS 6.5
CVE-2026-33141
MEDIUM
Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data
CVSS 6.5
CVE-2026-35662
MEDIUM
OpenClaw < 2026.3.22 - Missing controlScope Enforcement in Send Action
CVSS 4.3
CVE-2026-35660
HIGH
OpenClaw < 2026.3.23 - Insufficient Access Control in Gateway Agent Session Reset
CVSS 8.1
CVE-2026-35621
MEDIUM
OpenClaw < 2026.3.24 - Privilege Escalation via chat.send to Allowlist Persistence
CVSS 6.5
CVE-2026-35620
MEDIUM
OpenClaw < 2026.3.24 - Missing Authorization in /send and /allowlist Chat Commands
CVSS 5.4
CVE-2026-35598
MEDIUM
Vikunja has Missing Authorization on CalDAV Task Read
CVSS 4.3
CVE-2026-4162
HIGH
Gravity SMTP <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Plugin Uninstall
CVSS 7.1
CVE-2026-4977
MEDIUM
UsersWP <= 1.2.58 - Authenticated (Subscriber+) Restricted Usermeta Modification via 'htmlvar' Parameter
CVSS 4.3
CVE-2026-4057
MEDIUM
Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal
CVSS 4.3
CVE-2026-3360
HIGH
Tutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter
CVSS 7.5
CVE-2026-40117
MEDIUM
PraisonAIAgents Affected by Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
CVSS 6.2
CVE-2026-35631
MEDIUM
OpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat Commands
CVSS 6.5
CVE-2026-33785
HIGH
Junos OS: MX Series: Missing Authorization for specific 'request' CLI commands in a JDM/CSDS scenario
CVSS 8.8
CVE-2026-33776
MEDIUM
Junos OS and Junos OS Evolved: Specific low privileged CLI command exposes sensitive information
CVSS 5.5
CVE-2026-35063
HIGH
Missing Authorization in OpenPLC_V3
CVSS 8.8
CVE-2026-34184
CRITICAL
Missing Authorization in Hydrosystem Control System
CVSS 9.1
CVE-2026-1830
CRITICAL
Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload
CVSS 9.8
CVE-2026-4124
MEDIUM
Ziggeo <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'ziggeo_ajax' AJAX Action
CVSS 5.4
CVE-2026-4326
HIGH
Vertex Addons for Elementor <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins'
CVSS 8.8
CVE-2026-4916
LOW
Missing Authorization in GitLab
CVSS 2.7
CVE-2026-39429
HIGH
kcp's cache server is accessible without authentication or authorization checks
CVSS 8.2
CVE-2026-34837
MEDIUM
Zammad is miissing authorization in AI assistance controller for context data used in text tools
CVSS 4.3
CVE-2026-34782
MEDIUM
Zammad has improper access control in AI assistance controller for text tools
CVSS 4.3
Details
Vulnerabilities
7,700
Exploit Likelihood
High