CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,799 vulnerabilities with CWE-862
CVE-2026-12082 HIGH
Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)
CVSS 7.5
CVE-2026-13078 HIGH
Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader
CVSS 7.7
CVE-2026-7328 MEDIUM
Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service
CVE-2026-65011 MEDIUM
Graylog2 Server Missing Permission Check on Event Definition Duplicate
CVSS 4.3
CVE-2026-16544 MEDIUM
Awx: websocket eventconsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure
CVSS 6.5
CVE-2026-63262 MEDIUM
Missing Authorization in Kibana Leading to Information Disclosure
CVSS 4.3
CVE-2026-63143 MEDIUM
Missing Authorization in Kibana Leading to Unauthorized Information Disclosure
CVSS 4.3
CVE-2026-63141 MEDIUM
Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions
CVSS 6.3
CVE-2026-61267 HIGH
Oracle Hcm Configuration Workbench < 12.2.15 - Denial of Service
CVSS 7.3
CVE-2026-60953 HIGH
Oracle Telecom Billing Integrator 12.2.3-12.2.15 - Unauthorized Data Access/Modification
CVSS 8.1
CVE-2026-65055 MEDIUM
Taiga taiga-back Private Project Member Roster Disclosure via Unauthenticated filters_data Endpoints
CVSS 5.3
CVE-2026-63092 MEDIUM
kirby-modules License Key Disclosure via modules/activate Dialog
CVSS 4.3
CVE-2026-47688 HIGH
FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules
CVSS 8.2
CVE-2026-47657 HIGH
HumHub Missing Authorization on Remove All Space Members Action
CVE-2026-47416 CRITICAL
PraisonAI Platform < 0.1.4 Member Role Endpoint - Privilege Escalation
CVSS 9.6
CVE-2026-47413 CRITICAL
praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members
CVSS 9.6
CVE-2026-47412 HIGH
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
CVSS 8.1
CVE-2026-47411 MEDIUM
PraisonAI Platform < 0.1.4 Workspace Settings - Authorization Bypass
CVSS 6.5
CVE-2026-47409 HIGH
PraisonAI Platform < 0.1.4 Member Delete Endpoint - Owner Lockout
CVSS 8.1
CVE-2026-47405 HIGH
PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership
CVSS 8.8
CVE-2026-16454 MEDIUM
Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware Exfiltration
CVSS 4.3
CVE-2026-47394 HIGH
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-28310 CRITICAL
SolarWinds Serv-U Privilege Escalation Vulnerability
CVSS 9.1
CVE-2026-28309 CRITICAL
SolarWinds Serv-U Broken Access Control Vulnerability
CVSS 9.1
CVE-2026-65050 MEDIUM
Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors
CVSS 6.5
Details
Vulnerabilities 8,799
Exploit Likelihood High