The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,804 vulnerabilities with CWE-862
CVE-2026-11868
MEDIUM
WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
CVSS 5.3
CVE-2026-16216
MEDIUM
geex-arts django-jet OAuth cross-site request forgery
CVSS 4.3
CVE-2026-16215
MEDIUM
geex-arts django-jet OAuth Credential Revoke authorization
CVSS 6.5
CVE-2026-16197
MEDIUM
Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization
CVSS 6.3
CVE-2026-16123
MEDIUM
nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization
CVSS 6.3
CVE-2026-16081
MEDIUM
Sipeed PicoClaw auth.go cross-site request forgery
CVSS 4.3
CVE-2026-55518
CRITICAL
Avo < 3.32.1 and 4.0.0-beta.51 - Association Authorization Bypass
CVSS 9.6
CVE-2026-45704
HIGH
Pimcore: CustomReports Share Bypass
CVE-2026-45260
HIGH
Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling
CVSS 8.1
CVE-2026-45703
MEDIUM
Pimcore: WordExport Authorization Bypass for Unauthorized Document Export
CVSS 6.4
CVE-2026-48014
MEDIUM
Shopware: Admin API ACL Bypass in Order State Transition Endpoints
CVSS 6.5
CVE-2026-48008
MEDIUM
Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
CVSS 6.5
CVE-2026-16106
MEDIUM
Red Hat Keycloak Admin REST API - Incorrect Authorization in Role Deletion
CVSS 4.9
CVE-2026-12694
CRITICAL
Missing Authorization in Vimesoft's Enterprise Video Platform
CVSS 9.1
CVE-2026-63100
MEDIUM
Maybe 0.6.0 Missing Authorization via HostingsController show/update
CVSS 6.5
CVE-2026-15783
MEDIUM
Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
CVE-2026-12715
HIGH
Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft
CVE-2026-16017
MEDIUM
mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
CVSS 6.3
CVE-2026-11575
HIGH
PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback
CVSS 7.5
CVE-2026-15349
MEDIUM
Complete Hr, Accounting & Crm Suite Built For WooCommerce < 1.17.6 - Authorization Bypass
CVSS 4.3
CVE-2026-13765
HIGH
ThimPress LearnPress <= 4.4.1 - Unauthenticated Quiz Answer Disclosure
CVSS 7.5
CVE-2026-8616
MEDIUM
Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action
CVSS 5.3
CVE-2026-62235
MEDIUM
Grav Flex-Objects < 1.4.3 Authorization Bypass via API
CVSS 6.3
CVE-2026-62233
HIGH
grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey
CVSS 8.8
CVE-2026-62232
HIGH
Grav < 2.0.4 2FA Bypass via Secret Regeneration
CVSS 7.4
Details
Vulnerabilities
8,804
Exploit Likelihood
High