CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 104 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-15327 | Hig | 0.47 | 7.2 | 0.01 | Oct 31, 2018 | In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be… | ||
| CVE-2009-3168 | Hig | 0.47 | 7.2 | 0.03 | Sep 11, 2009 | Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request. | ||
| CVE-2026-71308 | Hig | 0.46 | 8.1 | 0.00 | Aug 18, 2026 | Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a CertificatePermission check. Assigning those… | ||
| CVE-2026-75846 | Hig | 0.46 | 7.1 | 0.00 | Aug 18, 2026 | ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a server-side function without any checkPermissionsOnDatabase… | ||
| CVE-2026-75109 | Hig | 0.46 | 7.1 | 0.00 | Aug 17, 2026 | Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own. | ||
| CVE-2026-73658 | Hig | 0.46 | 8.2 | 0.00 | Aug 13, 2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname,… | ||
| CVE-2026-72675 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a… | ||
| CVE-2026-28173 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions. | ||
| CVE-2026-27535 | Hig | 0.46 | 7.1 | 0.00 | Aug 13, 2026 | Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. | ||
| CVE-2026-16494 | Hig | 0.46 | 7.1 | 0.00 | Aug 12, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization… | ||
| CVE-2026-64954 | Hig | 0.46 | 8.2 | 0.00 | Aug 12, 2026 | Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows… | ||
| CVE-2026-48763 | Hig | 0.46 | 8.2 | 0.00 | Aug 11, 2026 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact… | ||
| CVE-2026-47765 | Hig | 0.46 | — | 0.00 | Aug 6, 2026 | Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This… | ||
| CVE-2026-18277 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the… | ||
| CVE-2026-66470 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||
| CVE-2026-65554 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. | ||
| CVE-2026-70617 | Hig | 0.46 | 8.1 | 0.00 | Aug 5, 2026 | Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can… | ||
| CVE-2026-70494 | Hig | 0.46 | 8.1 | 0.00 | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete… | ||
| CVE-2026-13227 | Hig | 0.46 | — | 0.00 | Aug 4, 2026 | An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0. | ||
| CVE-2026-13229 | Hig | 0.46 | — | 0.00 | Aug 4, 2026 | Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint. |
- risk 0.47cvss 7.2epss 0.01
In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be…
- risk 0.47cvss 7.2epss 0.03
Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request.
- risk 0.46cvss 8.1epss 0.00
Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a CertificatePermission check. Assigning those…
- risk 0.46cvss 7.1epss 0.00
ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a server-side function without any checkPermissionsOnDatabase…
- risk 0.46cvss 7.1epss 0.00
Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own.
- risk 0.46cvss 8.2epss 0.00
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname,…
- risk 0.46cvss 7.1epss 0.00
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a…
- risk 0.46cvss 7.1epss 0.00
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
- risk 0.46cvss 7.1epss 0.00
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
- risk 0.46cvss 7.1epss 0.00
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization…
- risk 0.46cvss 8.2epss 0.00
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows…
- risk 0.46cvss 8.2epss 0.00
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact…
- risk 0.46cvss —epss 0.00
Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This…
- risk 0.46cvss 7.1epss 0.00
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the…
- risk 0.46cvss 7.1epss 0.00
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
- risk 0.46cvss 7.1epss 0.00
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
- risk 0.46cvss 8.1epss 0.00
Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can…
- risk 0.46cvss 8.1epss 0.00
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete…
- risk 0.46cvss —epss 0.00
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0.
- risk 0.46cvss —epss 0.00
Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.