The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,230 vulnerabilities with CWE-862
CVE-2026-1722
MEDIUM
WCFM Marketplace - Insecure Direct Object Reference
CVSS 5.3
CVE-2026-24327
MEDIUM
SAP Strategic Enterprise Management - Info Disclosure
CVSS 4.3
CVE-2026-24326
MEDIUM
SAP S/4HANA Defense & Security - Missing Authorization Check in Disconnected Operations
CVSS 4.3
CVE-2026-24322
HIGH
SAP Solution Tools Plug-In - Authenticated Information Disclosure via Missing Authorization
CVSS 7.7
CVE-2026-24312
MEDIUM
SAP Business Workflow - Privilege Escalation
CVSS 5.2
CVE-2026-23688
MEDIUM
SAP Fiori App Manage Service Entry Sheets - Privilege Escalation
CVSS 4.3
CVE-2026-23681
MEDIUM
SAP Support Tools Plug-In - Info Disclosure
CVSS 4.3
CVE-2026-0509
CRITICAL
SAP NetWeaver Application Server ABAP/ABAP Platform - Privilege Esc...
CVSS 9.6
CVE-2026-0490
HIGH
SAP BusinessObjects BI Platform - Auth Bypass
CVSS 7.5
CVE-2026-0488
CRITICAL
SAP CRM/S/4HANA - Privilege Escalation
CVSS 9.9
CVE-2026-0486
MEDIUM
SAP Solution Tools Plug-In - Missing Authorization
CVSS 5.0
CVE-2026-0484
MEDIUM
SAP NetWeaver/S/4HANA - Privilege Escalation
CVSS 6.5
CVE-2026-0845
HIGH
WCFM - Frontend Manager <6.7.24 - Privilege Escalation
CVSS 7.2
CVE-2026-25939
CRITICAL
FUXA 1.2.8-1.2.10 - Unauthenticated Authorization Bypass via Scheduler Modification
CVSS 9.1
CVE-2026-25808
HIGH
Hollo <0.6.20-0.7.2 - Info Disclosure
CVSS 7.5
CVE-2026-25876
CRITICAL
PlaciPy 1.0.0 - Missing Object-Level Authorization in Results Endpoint
CVSS 9.1
CVE-2026-25810
CRITICAL
PlaciPy 1.0.0 - Missing Object-Level Authorization in Student Submission Routes
CVSS 9.1
CVE-2026-25806
MEDIUM
PlaciPy 1.0.0 - Missing Authorization in Student API Endpoints
CVSS 6.5
CVE-2026-24777
MEDIUM
OpenProject < 17.0.2 - Missing Authorization for User Lock/Unlock
CVSS 6.7
CVE-2026-24095
MEDIUM
Checkmk <2.4.0p21-2.3.0p43-2.2.0 - Auth Bypass
CVE-2026-2208
MEDIUM
Wekan < 8.21 - Missing Authorization in Rules Handler
CVSS 4.3
CVE-2026-2065
MEDIUM
Flycatcher Toys smART Pixelator 2.0 - Auth Bypass
CVSS 6.3
CVE-2026-25752
CRITICAL
FUXA < 1.2.10 - Unauthenticated Authorization Bypass via WebSocket Device Tag Modification
CVSS 9.1
CVE-2026-23632
MEDIUM
Gogs < 0.13.4 - Incorrect Authorization via PUT /repos/:owner/:repo/contents/* Endpoint
CVSS 6.5
CVE-2026-22592
MEDIUM
Gogs < 0.13.4 - Authenticated Denial of Service via Repository File Deletion
CVSS 6.5
Details
Vulnerabilities
8,230
Exploit Likelihood
High