CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,230 vulnerabilities with CWE-862
CVE-2026-1722 MEDIUM
WCFM Marketplace - Insecure Direct Object Reference
CVSS 5.3
CVE-2026-24327 MEDIUM
SAP Strategic Enterprise Management - Info Disclosure
CVSS 4.3
CVE-2026-24326 MEDIUM
SAP S/4HANA Defense & Security - Missing Authorization Check in Disconnected Operations
CVSS 4.3
CVE-2026-24322 HIGH
SAP Solution Tools Plug-In - Authenticated Information Disclosure via Missing Authorization
CVSS 7.7
CVE-2026-24312 MEDIUM
SAP Business Workflow - Privilege Escalation
CVSS 5.2
CVE-2026-23688 MEDIUM
SAP Fiori App Manage Service Entry Sheets - Privilege Escalation
CVSS 4.3
CVE-2026-23681 MEDIUM
SAP Support Tools Plug-In - Info Disclosure
CVSS 4.3
CVE-2026-0509 CRITICAL
SAP NetWeaver Application Server ABAP/ABAP Platform - Privilege Esc...
CVSS 9.6
CVE-2026-0490 HIGH
SAP BusinessObjects BI Platform - Auth Bypass
CVSS 7.5
CVE-2026-0488 CRITICAL
SAP CRM/S/4HANA - Privilege Escalation
CVSS 9.9
CVE-2026-0486 MEDIUM
SAP Solution Tools Plug-In - Missing Authorization
CVSS 5.0
CVE-2026-0484 MEDIUM
SAP NetWeaver/S/4HANA - Privilege Escalation
CVSS 6.5
CVE-2026-0845 HIGH
WCFM - Frontend Manager <6.7.24 - Privilege Escalation
CVSS 7.2
CVE-2026-25939 CRITICAL
FUXA 1.2.8-1.2.10 - Unauthenticated Authorization Bypass via Scheduler Modification
CVSS 9.1
CVE-2026-25808 HIGH
Hollo <0.6.20-0.7.2 - Info Disclosure
CVSS 7.5
CVE-2026-25876 CRITICAL
PlaciPy 1.0.0 - Missing Object-Level Authorization in Results Endpoint
CVSS 9.1
CVE-2026-25810 CRITICAL
PlaciPy 1.0.0 - Missing Object-Level Authorization in Student Submission Routes
CVSS 9.1
CVE-2026-25806 MEDIUM
PlaciPy 1.0.0 - Missing Authorization in Student API Endpoints
CVSS 6.5
CVE-2026-24777 MEDIUM
OpenProject < 17.0.2 - Missing Authorization for User Lock/Unlock
CVSS 6.7
CVE-2026-24095 MEDIUM
Checkmk <2.4.0p21-2.3.0p43-2.2.0 - Auth Bypass
CVE-2026-2208 MEDIUM
Wekan < 8.21 - Missing Authorization in Rules Handler
CVSS 4.3
CVE-2026-2065 MEDIUM
Flycatcher Toys smART Pixelator 2.0 - Auth Bypass
CVSS 6.3
CVE-2026-25752 CRITICAL
FUXA < 1.2.10 - Unauthenticated Authorization Bypass via WebSocket Device Tag Modification
CVSS 9.1
CVE-2026-23632 MEDIUM
Gogs < 0.13.4 - Incorrect Authorization via PUT /repos/:owner/:repo/contents/* Endpoint
CVSS 6.5
CVE-2026-22592 MEDIUM
Gogs < 0.13.4 - Authenticated Denial of Service via Repository File Deletion
CVSS 6.5
Details
Vulnerabilities 8,230
Exploit Likelihood High