CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,799 vulnerabilities with CWE-862
CVE-2026-11876 MEDIUM
Missing Authorization in get_deployed_stack Endpoint in zenml-io/zenml
CVSS 5.0
CVE-2026-6792 MEDIUM
Improper Authorization in Universal Sotware's FlexCity
CVSS 6.5
CVE-2026-65007 CRITICAL
Grav before 1.0.8 Missing Authorization on API Key Generation
CVSS 9.6
CVE-2026-1372 MEDIUM
Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation
CVSS 4.3
CVE-2026-8593 MEDIUM
Checkmk - Fix Business Intelligence API Pack Permission
CVE-2026-14185 MEDIUM
WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update
CVSS 4.3
CVE-2026-13694 MEDIUM
Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass
CVSS 6.5
CVE-2026-57494 HIGH
AgenticMail: Cross-agent task authorization bypass in AgenticMail API
CVE-2026-55550 HIGH
NextCRM 0.12.1 - Product Catalog RBAC Bypass via MCP Tools
CVSS 7.1
CVE-2026-55544 HIGH
NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and Tampering
CVSS 7.6
CVE-2026-47129 HIGH
NextCRM < 0.12.0 - Authenticated Account Activation Bypass
CVSS 8.1
CVE-2026-44585 MEDIUM
Paymenter: Broken object level authorization via service reference manipulation on ticket creation
CVSS 5.4
CVE-2026-45295 MEDIUM
FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint
CVSS 6.5
CVE-2026-58482 MEDIUM
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
CVSS 5.9
CVE-2026-64622 HIGH
Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox
CVSS 7.5
CVE-2026-63758 MEDIUM
SurrealDB before 3.1.0 Authorization Bypass via KILL Statement
CVSS 5.4
CVE-2026-63741 MEDIUM
SurrealDB before 3.1.0 Authentication Bypass via USE statement
CVSS 6.5
CVE-2026-13432 MEDIUM
ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation
CVSS 5.4
CVE-2026-12973 MEDIUM
PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification
CVSS 6.5
CVE-2026-12723 MEDIUM
Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library
CVSS 5.3
CVE-2026-11868 MEDIUM
WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
CVSS 5.3
CVE-2026-16216 MEDIUM
geex-arts django-jet OAuth cross-site request forgery
CVSS 4.3
CVE-2026-16215 MEDIUM
geex-arts django-jet OAuth Credential Revoke authorization
CVSS 6.5
CVE-2026-16197 MEDIUM
Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization
CVSS 6.3
CVE-2026-16123 MEDIUM
nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization
CVSS 6.3
Details
Vulnerabilities 8,799
Exploit Likelihood High