VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,117)

page 17 of 506
  • CVE-2026-100240CriSep 29, 2026
    risk 0.59cvss 9.1epss 0.00

    Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10.

  • CVE-2026-78361CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary…

  • CVE-2026-68484CriSep 9, 2026
    risk 0.59cvss —epss 0.00

    Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.

  • CVE-2026-41869CriSep 9, 2026
    risk 0.59cvss 9.1epss 0.01

    Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an…

  • CVE-2026-69641CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.01

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-86840CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.00

    The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on…

  • CVE-2026-78328CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.00

    A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

  • CVE-2026-79058CriAug 25, 2026
    risk 0.59cvss 9.1epss 0.00

    Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-71933CriAug 24, 2026
    risk 0.59cvss 9.1epss 0.01

    Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart…

  • CVE-2026-75866CriAug 22, 2026
    risk 0.59cvss 9.1epss 0.01

    Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client…

  • CVE-2026-58433CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.01

    Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

  • CVE-2026-16038CriAug 7, 2026
    risk 0.59cvss 9.1epss 0.00

    The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and…

  • CVE-2026-5581CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.01

    The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via…

  • CVE-2026-4431CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.01

    The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for…

  • CVE-2026-57116criJun 18, 2026
    risk 0.59cvss —epss —

    # AgentOS remains unauthenticated after GHSA-pm96 patched version and allows remote agent invocation ## Summary PraisonAI's `AgentOS` FastAPI deployment surface remains unauthenticated in current main and in releases after the published patched version for…

  • CVE-2026-57118criJun 18, 2026
    risk 0.59cvss —epss —

    # PraisonAI `AgentTeam.launch()` exposes unauthenticated remote agent invocation endpoints ## Summary PraisonAI's documented Python `AgentTeam.launch()` / `Agents.launch()` HTTP server starts externally reachable agent invocation endpoints without any authentication…

  • CVE-2026-24611CriJun 17, 2026
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.

  • CVE-2026-48881CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

  • CVE-2026-45550CriJun 10, 2026
    risk 0.59cvss 9.1epss 0.00

    Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group,…

  • CVE-2026-42682CriJun 1, 2026
    risk 0.59cvss 9.1epss 0.00

    Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.