CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,261 vulnerabilities with CWE-862
CVE-2026-23477 HIGH
Rocket.Chat <6.12.0 - Info Disclosure
CVSS 7.7
CVE-2026-0635 MEDIUM
Responsive Accordion Slider <1.2.2 - Info Disclosure
CVSS 4.3
CVE-2026-0511 HIGH
SAP Fiori App - Privilege Escalation
CVSS 8.1
CVE-2026-0506 HIGH
SAP NetWeaver Application Server ABAP - Authenticated Missing Authorization Check via RFC Function
CVSS 8.1
CVE-2026-0503 MEDIUM
SAP ERP Central Component and SAP S/4HANA (SAP EHS Management) - Missing Authorization Check
CVSS 6.4
CVE-2026-0497 MEDIUM
SAP Product Designer Web UI - Info Disclosure
CVSS 4.3
CVE-2026-0817 MEDIUM
MediaWiki CampaignEvents 1.39, 1.43-1.45 - Missing Authorization
CVSS 5.3
CVE-2026-22522 MEDIUM
Munir Kamal Block Slider <2.2.3 - Privilege Escalation
CVSS 6.5
CVE-2026-22517 MEDIUM
GA4WP: Google Analytics for WordPress <2.10.0 - Auth Bypass
CVSS 5.4
CVE-2026-22492 MEDIUM
Nawawi Jamili Docket Cache <24.07.04 - Info Disclosure
CVSS 4.3
CVE-2026-22490 MEDIUM
WordPress LPagery <= 2.4.9 - Missing Authorization Access Control Bypass
CVSS 5.4
CVE-2026-22488 MEDIUM
IdeaBox Creations Dashboard Welcome <1.0.8 - Info Disclosure
CVSS 5.3
CVE-2026-22487 MEDIUM
baqend Speed Kit <2.0.2 - Info Disclosure
CVSS 4.3
CVE-2026-22486 MEDIUM
Hakob Re Gallery & Responsive Photo Gallery Plugin <1.17.18 - RCE
CVSS 5.3
CVE-2026-0676 MEDIUM
G5Theme Zorka <= 1.5.7 - Info Disclosure
CVSS 5.3
CVE-2026-0674 MEDIUM
Campaign Monitor for WordPress <2.9.0 - RCE
CVSS 4.3
CVE-2026-0656 HIGH
iPaymu Payment Gateway <2.0.2 - Missing Authentication
CVSS 8.2
CVE-2026-0628 HIGH
Google Chrome < 143.0.7499.192 - Insufficient Policy Enforcement in WebView Tag
CVSS 8.8
CVE-2026-21429 MEDIUM
emlog 2.5.23 - Missing Authorization
CVSS 4.3
CVE-2025-69189 HIGH
WordPress JobBank plugin <= 1.2.3 - Broken Access Control vulnerability
CVSS 7.3
CVE-2025-69137 MEDIUM
WordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerability
CVSS 6.5
CVE-2025-69103 HIGH
WordPress Brikk theme <= 3.0.0 - Arbitrary Content Deletion vulnerability
CVSS 7.5
CVE-2025-48640 HIGH
Android - Missing Permission Check for 3rd Party Passkey Pairing Approval
CVSS 8.0
CVE-2025-48617 HIGH
Android - Local Privilege Escalation via CarrierConfigLoader Permissions Bypass
CVSS 7.8
CVE-2025-14272 HIGH
Rockwell Automation FactoryTalk Analytics PavilionX
Details
Vulnerabilities 8,261
Exploit Likelihood High