The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,133 vulnerabilities with CWE-862
CVE-2026-45285
MEDIUM
Nextcloud 32.0.0-32.0.8 and 33.0.0-33.0.2 - Unauthenticated Data Access via Auto-Generated Public Link
CVSS 6.4
CVE-2026-45267
MEDIUM
Nextcloud: Missing permission check for from submissions
CVSS 6.5
CVE-2026-42677
HIGH
WordPress WP Document Revisions plugin <= 3.8.1 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-42675
HIGH
WordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerability
CVSS 7.3
CVE-2026-42671
MEDIUM
WordPress GeoDirectory plugin <= 2.8.157 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-42682
CRITICAL
WordPress wpForo Forum plugin <= 3.0.6 - Broken Access Control vulnerability
CVSS 9.1
CVE-2026-41014
MEDIUM
Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints
CVSS 4.3
CVE-2026-40543
HIGH
Missing Authorization in SOPlanning
CVE-2026-8382
MEDIUM
Advanced Custom Fields (ACF®) <= 6.8.1 - Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters
CVSS 5.3
CVE-2026-48811
MEDIUM
FreeScout: Thread Deletion Bypasses Mailbox Access Revocation
CVSS 4.3
CVE-2026-49385
MEDIUM
Jetbrains YouTrack < 2026.1.13570 - Missing Authorization
CVSS 6.5
CVE-2026-49378
MEDIUM
Jetbrains TeamCity < 2026.1 - Missing Authorization
CVSS 4.3
CVE-2026-49374
HIGH
Jetbrains TeamCity < 2026.1 - Missing Authorization
CVSS 7.6
CVE-2026-49367
HIGH
Jetbrains IntelliJ Idea < 2026.1.1 - Missing Authorization
CVSS 8.0
CVE-2026-47745
MEDIUM
Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables
CVSS 6.5
CVE-2026-47742
MEDIUM
Shopper: Missing authorization on Product admin Livewire sub-form components
CVSS 6.5
CVE-2026-47740
HIGH
Shopper: Authorization bypass in multiple Livewire admin components
CVSS 8.1
CVE-2026-47125
HIGH
Arcane: Missing admin authorization on global variables endpoint
CVSS 8.8
CVE-2026-45632
CRITICAL
Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution
CVSS 9.9
CVE-2026-45625
CRITICAL
Arcane Git Repository Endpoints - Missing Admin Authorization
CVSS 9.9
CVE-2026-35630
HIGH
OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons
CVSS 8.0
CVE-2026-32905
HIGH
OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command
CVSS 8.3
CVE-2026-4290
CRITICAL
WP Travel Pro <= 10.6.0 - Missing Authorization to Unauthenticated Arbitrary User Deletion Including Administrators
CVSS 9.1
CVE-2026-44884
MEDIUM
Portainer: Missing authorization on custom template file endpoint exposes template content
CVSS 6.5
CVE-2026-44849
HIGH
Portainer: Endpoint security bypass via Swarm service create/update
CVSS 8.8
Details
Vulnerabilities
8,133
Exploit Likelihood
High