CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,804 vulnerabilities with CWE-862
CVE-2026-11868 MEDIUM
WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
CVSS 5.3
CVE-2026-16216 MEDIUM
geex-arts django-jet OAuth cross-site request forgery
CVSS 4.3
CVE-2026-16215 MEDIUM
geex-arts django-jet OAuth Credential Revoke authorization
CVSS 6.5
CVE-2026-16197 MEDIUM
Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization
CVSS 6.3
CVE-2026-16123 MEDIUM
nextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization
CVSS 6.3
CVE-2026-16081 MEDIUM
Sipeed PicoClaw auth.go cross-site request forgery
CVSS 4.3
CVE-2026-55518 CRITICAL
Avo < 3.32.1 and 4.0.0-beta.51 - Association Authorization Bypass
CVSS 9.6
CVE-2026-45704 HIGH
Pimcore: CustomReports Share Bypass
CVE-2026-45260 HIGH
Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling
CVSS 8.1
CVE-2026-45703 MEDIUM
Pimcore: WordExport Authorization Bypass for Unauthorized Document Export
CVSS 6.4
CVE-2026-48014 MEDIUM
Shopware: Admin API ACL Bypass in Order State Transition Endpoints
CVSS 6.5
CVE-2026-48008 MEDIUM
Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
CVSS 6.5
CVE-2026-16106 MEDIUM
Red Hat Keycloak Admin REST API - Incorrect Authorization in Role Deletion
CVSS 4.9
CVE-2026-12694 CRITICAL
Missing Authorization in Vimesoft's Enterprise Video Platform
CVSS 9.1
CVE-2026-63100 MEDIUM
Maybe 0.6.0 Missing Authorization via HostingsController show/update
CVSS 6.5
CVE-2026-15783 MEDIUM
Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
CVE-2026-12715 HIGH
Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft
CVE-2026-16017 MEDIUM
mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
CVSS 6.3
CVE-2026-11575 HIGH
PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback
CVSS 7.5
CVE-2026-15349 MEDIUM
Complete Hr, Accounting & Crm Suite Built For WooCommerce < 1.17.6 - Authorization Bypass
CVSS 4.3
CVE-2026-13765 HIGH
ThimPress LearnPress <= 4.4.1 - Unauthenticated Quiz Answer Disclosure
CVSS 7.5
CVE-2026-8616 MEDIUM
Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action
CVSS 5.3
CVE-2026-62235 MEDIUM
Grav Flex-Objects < 1.4.3 Authorization Bypass via API
CVSS 6.3
CVE-2026-62233 HIGH
grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey
CVSS 8.8
CVE-2026-62232 HIGH
Grav < 2.0.4 2FA Bypass via Secret Regeneration
CVSS 7.4
Details
Vulnerabilities 8,804
Exploit Likelihood High