CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,804 vulnerabilities with CWE-862
CVE-2026-62218 HIGH
OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve
CVSS 8.8
CVE-2026-62207 HIGH
OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools
CVSS 8.8
CVE-2026-62206 HIGH
OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions
CVSS 7.1
CVE-2026-62205 HIGH
OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions
CVSS 7.1
CVE-2026-45334 MEDIUM
Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
CVE-2026-44176 MEDIUM
Kirby: `pages.access` permission is not checked during rendering of page drafts
CVE-2026-61718 MEDIUM
bunkerweb: Read-only Web UI users can delete job cache files due to missing authorization on /cache/ routes
CVSS 5.4
CVE-2026-47089 MEDIUM
Cyrusimap Cyrus Imap < 3.12.3 - Missing Authorization
CVSS 4.3
CVE-2026-46515 CRITICAL
Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution
CVE-2026-55548 MEDIUM
Yamcs < 5.12.8 and 5.13.0-5.13.1 - Telemetry Packet Authorization Bypass
CVSS 4.3
CVE-2026-44595 MEDIUM
YAMCS yamcs-core 5.12.7 - User Enumeration
CVSS 4.3
CVE-2026-63082 MEDIUM
Perfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment
CVSS 5.4
CVE-2026-57206 HIGH
SimpleChat plugin validation endpoints missing authentication and authorization
CVSS 8.6
CVE-2026-57205 MEDIUM
SimpleChat: Authenticated users can access other users' profile metadata through user IDOR endpoints
CVSS 4.3
CVE-2026-55440 MEDIUM
Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of service
CVSS 6.5
CVE-2026-54568 MEDIUM
Microsoft UFO 3.0.0 to < 3.0.6 - Device Info Authorization Bypass
CVSS 4.3
CVE-2026-15610 MEDIUM
WPBot <= 8.5.6 - Subscriber RAG Document Re-Sync Authorization Bypass
CVSS 4.3
CVE-2026-15407 MEDIUM
Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action
CVSS 4.3
CVE-2026-15350 MEDIUM
The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameter
CVSS 4.3
CVE-2026-15106 MEDIUM
WPBot <= 8.5.6 - Unauthenticated Chat Session Deletion Authorization Bypass
CVSS 5.3
CVE-2026-12907 LOW
RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation
CVSS 2.7
CVE-2026-15336 MEDIUM
Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter
CVSS 4.3
CVE-2026-12434 MEDIUM
List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute
CVSS 4.3
CVE-2026-53447 MEDIUM
Wekan < 9.35 cloneBoard - Private Board Information Disclosure
CVSS 6.5
CVE-2026-53445 HIGH
Wekan: Authorization bypass in copyBoard DDP method allows any user to copy private boards
Details
Vulnerabilities 8,804
Exploit Likelihood High