The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,799 vulnerabilities with CWE-862
CVE-2026-12082
HIGH
Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)
CVSS 7.5
CVE-2026-13078
HIGH
Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader
CVSS 7.7
CVE-2026-7328
MEDIUM
Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service
CVE-2026-65011
MEDIUM
Graylog2 Server Missing Permission Check on Event Definition Duplicate
CVSS 4.3
CVE-2026-16544
MEDIUM
Awx: websocket eventconsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure
CVSS 6.5
CVE-2026-63262
MEDIUM
Missing Authorization in Kibana Leading to Information Disclosure
CVSS 4.3
CVE-2026-63143
MEDIUM
Missing Authorization in Kibana Leading to Unauthorized Information Disclosure
CVSS 4.3
CVE-2026-63141
MEDIUM
Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions
CVSS 6.3
CVE-2026-61267
HIGH
Oracle Hcm Configuration Workbench < 12.2.15 - Denial of Service
CVSS 7.3
CVE-2026-60953
HIGH
Oracle Telecom Billing Integrator 12.2.3-12.2.15 - Unauthorized Data Access/Modification
CVSS 8.1
CVE-2026-65055
MEDIUM
Taiga taiga-back Private Project Member Roster Disclosure via Unauthenticated filters_data Endpoints
CVSS 5.3
CVE-2026-63092
MEDIUM
kirby-modules License Key Disclosure via modules/activate Dialog
CVSS 4.3
CVE-2026-47688
HIGH
FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules
CVSS 8.2
CVE-2026-47657
HIGH
HumHub Missing Authorization on Remove All Space Members Action
CVE-2026-47416
CRITICAL
PraisonAI Platform < 0.1.4 Member Role Endpoint - Privilege Escalation
CVSS 9.6
CVE-2026-47413
CRITICAL
praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members
CVSS 9.6
CVE-2026-47412
HIGH
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
CVSS 8.1
CVE-2026-47411
MEDIUM
PraisonAI Platform < 0.1.4 Workspace Settings - Authorization Bypass
CVSS 6.5
CVE-2026-47409
HIGH
PraisonAI Platform < 0.1.4 Member Delete Endpoint - Owner Lockout
CVSS 8.1
CVE-2026-47405
HIGH
PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership
CVSS 8.8
CVE-2026-16454
MEDIUM
Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware Exfiltration
CVSS 4.3
CVE-2026-47394
HIGH
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-28310
CRITICAL
SolarWinds Serv-U Privilege Escalation Vulnerability
CVSS 9.1
CVE-2026-28309
CRITICAL
SolarWinds Serv-U Broken Access Control Vulnerability
CVSS 9.1
CVE-2026-65050
MEDIUM
Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors
CVSS 6.5
Details
Vulnerabilities
8,799
Exploit Likelihood
High