CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,133 vulnerabilities with CWE-862
CVE-2026-45285 MEDIUM
Nextcloud 32.0.0-32.0.8 and 33.0.0-33.0.2 - Unauthenticated Data Access via Auto-Generated Public Link
CVSS 6.4
CVE-2026-45267 MEDIUM
Nextcloud: Missing permission check for from submissions
CVSS 6.5
CVE-2026-42677 HIGH
WordPress WP Document Revisions plugin <= 3.8.1 - Broken Access Control vulnerability
CVSS 7.5
CVE-2026-42675 HIGH
WordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerability
CVSS 7.3
CVE-2026-42671 MEDIUM
WordPress GeoDirectory plugin <= 2.8.157 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-42682 CRITICAL
WordPress wpForo Forum plugin <= 3.0.6 - Broken Access Control vulnerability
CVSS 9.1
CVE-2026-41014 MEDIUM
Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints
CVSS 4.3
CVE-2026-40543 HIGH
Missing Authorization in SOPlanning
CVE-2026-8382 MEDIUM
Advanced Custom Fields (ACF®) <= 6.8.1 - Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters
CVSS 5.3
CVE-2026-48811 MEDIUM
FreeScout: Thread Deletion Bypasses Mailbox Access Revocation
CVSS 4.3
CVE-2026-49385 MEDIUM
Jetbrains YouTrack < 2026.1.13570 - Missing Authorization
CVSS 6.5
CVE-2026-49378 MEDIUM
Jetbrains TeamCity < 2026.1 - Missing Authorization
CVSS 4.3
CVE-2026-49374 HIGH
Jetbrains TeamCity < 2026.1 - Missing Authorization
CVSS 7.6
CVE-2026-49367 HIGH
Jetbrains IntelliJ Idea < 2026.1.1 - Missing Authorization
CVSS 8.0
CVE-2026-47745 MEDIUM
Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables
CVSS 6.5
CVE-2026-47742 MEDIUM
Shopper: Missing authorization on Product admin Livewire sub-form components
CVSS 6.5
CVE-2026-47740 HIGH
Shopper: Authorization bypass in multiple Livewire admin components
CVSS 8.1
CVE-2026-47125 HIGH
Arcane: Missing admin authorization on global variables endpoint
CVSS 8.8
CVE-2026-45632 CRITICAL
Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution
CVSS 9.9
CVE-2026-45625 CRITICAL
Arcane Git Repository Endpoints - Missing Admin Authorization
CVSS 9.9
CVE-2026-35630 HIGH
OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons
CVSS 8.0
CVE-2026-32905 HIGH
OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command
CVSS 8.3
CVE-2026-4290 CRITICAL
WP Travel Pro <= 10.6.0 - Missing Authorization to Unauthenticated Arbitrary User Deletion Including Administrators
CVSS 9.1
CVE-2026-44884 MEDIUM
Portainer: Missing authorization on custom template file endpoint exposes template content
CVSS 6.5
CVE-2026-44849 HIGH
Portainer: Endpoint security bypass via Swarm service create/update
CVSS 8.8
Details
Vulnerabilities 8,133
Exploit Likelihood High