VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 15 of 463
  • CVE-2025-2407CriMay 27, 2025
    risk 0.60cvss epss 0.00

    Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vulnerability is fixed in Version 1.5.

  • CVE-2024-8074CriNov 12, 2024
    risk 0.60cvss epss 0.00

    Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users. This issue affects Nomysem: before 13.10.2024.

  • CVE-2023-25573HigMar 9, 2023
    risk 0.60cvss 8.6epss 0.52

    metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the…

  • CVE-2022-0218HigFeb 4, 2022
    risk 0.60cvss 8.3epss 0.71

    The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file,…

  • CVE-2020-1963CriJun 3, 2020
    risk 0.60cvss 9.1epss 0.05

    Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.

  • CVE-2017-5180HigFeb 9, 2017
    risk 0.60cvss 8.8epss 0.01

    Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the…

  • CVE-2026-58433CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.00

    Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

  • CVE-2026-16038CriAug 7, 2026
    risk 0.59cvss 9.1epss 0.00

    The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and…

  • CVE-2026-5581CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via…

  • CVE-2026-4431CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for…

  • CVE-2026-50006criJul 14, 2026
    risk 0.59cvss epss

    ## Summary Anyquery's `server` mode does not disable or restrict native SQLite disk manipulation commands. Unauthenticated attackers connecting to the MySQL-compatible server port can use the `ATTACH DATABASE` command to write arbitrary SQLite databases to any path on the…

  • CVE-2026-57139criJun 18, 2026
    risk 0.59cvss epss

    ## Summary The published npm package `praisonai` exports a TypeScript `MCPServer` that can expose tools, resources, and prompts over an HTTP JSON-RPC transport with: ```ts await server.start({ port: 3000 }); ``` The HTTP transport has no authentication or authorization path.…

  • CVE-2026-57116criJun 18, 2026
    risk 0.59cvss epss

    # AgentOS remains unauthenticated after GHSA-pm96 patched version and allows remote agent invocation ## Summary PraisonAI's `AgentOS` FastAPI deployment surface remains unauthenticated in current main and in releases after the published patched version for…

  • CVE-2026-57118criJun 18, 2026
    risk 0.59cvss epss

    # PraisonAI `AgentTeam.launch()` exposes unauthenticated remote agent invocation endpoints ## Summary PraisonAI's documented Python `AgentTeam.launch()` / `Agents.launch()` HTTP server starts externally reachable agent invocation endpoints without any authentication…

  • CVE-2026-57131criJun 18, 2026
    risk 0.59cvss epss

    # praisonai: Jobs API exposes agent-execution endpoints with no authentication **Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research **Target:** https://github.com/MervinPraison/PraisonAI --- **Package:** `praisonai` on PyPI…

  • CVE-2026-24611CriJun 17, 2026
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.

  • CVE-2026-48881CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

  • CVE-2026-45550CriJun 10, 2026
    risk 0.59cvss 9.1epss 0.00

    Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group,…

  • CVE-2026-42682CriJun 1, 2026
    risk 0.59cvss 9.1epss 0.00

    Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.

  • CVE-2026-4290CriMay 29, 2026
    risk 0.59cvss 9.1epss 0.00

    The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and…