The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,799 vulnerabilities with CWE-862
CVE-2026-11876
MEDIUM
Missing Authorization in get_deployed_stack Endpoint in zenml-io/zenml
CVSS 5.0
CVE-2026-6792
MEDIUM
Improper Authorization in Universal Sotware's FlexCity
CVSS 6.5
CVE-2026-65007
CRITICAL
Grav before 1.0.8 Missing Authorization on API Key Generation
CVSS 9.6
CVE-2026-1372
MEDIUM
Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation
CVSS 4.3
CVE-2026-8593
MEDIUM
Checkmk - Fix Business Intelligence API Pack Permission
CVE-2026-14185
MEDIUM
WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update
CVSS 4.3
CVE-2026-13694
MEDIUM
Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass
CVSS 6.5
CVE-2026-57494
HIGH
AgenticMail: Cross-agent task authorization bypass in AgenticMail API
CVE-2026-55550
HIGH
NextCRM 0.12.1 - Product Catalog RBAC Bypass via MCP Tools
CVSS 7.1
CVE-2026-55544
HIGH
NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and Tampering
CVSS 7.6
CVE-2026-47129
HIGH
NextCRM < 0.12.0 - Authenticated Account Activation Bypass
CVSS 8.1
CVE-2026-44585
MEDIUM
Paymenter: Broken object level authorization via service reference manipulation on ticket creation
CVSS 5.4
CVE-2026-45295
MEDIUM
FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint
CVSS 6.5
CVE-2026-58482
MEDIUM
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
CVSS 5.9
CVE-2026-64622
HIGH
Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox
CVSS 7.5
CVE-2026-63758
MEDIUM
SurrealDB before 3.1.0 Authorization Bypass via KILL Statement
CVSS 5.4
CVE-2026-63741
MEDIUM
SurrealDB before 3.1.0 Authentication Bypass via USE statement
CVSS 6.5
CVE-2026-13432
MEDIUM
ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation
CVSS 5.4
CVE-2026-12973
MEDIUM
PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification
CVSS 6.5
CVE-2026-12723
MEDIUM
Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library
CVSS 5.3
CVE-2026-11868
MEDIUM
WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
CVSS 5.3
CVE-2026-16216
MEDIUM
geex-arts django-jet OAuth cross-site request forgery
CVSS 4.3
CVE-2026-16215
MEDIUM
geex-arts django-jet OAuth Credential Revoke authorization
CVSS 6.5
CVE-2026-16197
MEDIUM
Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization
CVSS 6.3
CVE-2026-16123
MEDIUM
nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization
CVSS 6.3
Details
Vulnerabilities
8,799
Exploit Likelihood
High