CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (10,117)
page 17 of 506| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-100240 | Cri | 0.59 | 9.1 | 0.00 | Sep 29, 2026 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||
| CVE-2026-78361 | Cri | 0.59 | 9.1 | 0.00 | Sep 10, 2026 | The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary… | ||
| CVE-2026-68484 | Cri | 0.59 | — | 0.00 | Sep 9, 2026 | Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges. | ||
| CVE-2026-41869 | Cri | 0.59 | 9.1 | 0.01 | Sep 9, 2026 | Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an… | ||
| CVE-2026-69641 | Cri | 0.59 | 9.1 | 0.01 | Sep 8, 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-86840 | Cri | 0.59 | 9.1 | 0.00 | Sep 8, 2026 | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on… | ||
| CVE-2026-78328 | Cri | 0.59 | 9.1 | 0.00 | Sep 4, 2026 | A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin. | ||
| CVE-2026-79058 | Cri | 0.59 | 9.1 | 0.00 | Aug 25, 2026 | Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2026-71933 | Cri | 0.59 | 9.1 | 0.01 | Aug 24, 2026 | Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart… | ||
| CVE-2026-75866 | Cri | 0.59 | 9.1 | 0.01 | Aug 22, 2026 | Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client… | ||
| CVE-2026-58433 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | ||
| CVE-2026-16038 | Cri | 0.59 | 9.1 | 0.00 | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and… | ||
| CVE-2026-5581 | Cri | 0.59 | 9.1 | 0.01 | Aug 5, 2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via… | ||
| CVE-2026-4431 | Cri | 0.59 | 9.1 | 0.01 | Aug 5, 2026 | The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for… | ||
| CVE-2026-57116 | cri | 0.59 | — | — | Jun 18, 2026 | # AgentOS remains unauthenticated after GHSA-pm96 patched version and allows remote agent invocation ## Summary PraisonAI's `AgentOS` FastAPI deployment surface remains unauthenticated in current main and in releases after the published patched version for… | ||
| CVE-2026-57118 | cri | 0.59 | — | — | Jun 18, 2026 | # PraisonAI `AgentTeam.launch()` exposes unauthenticated remote agent invocation endpoints ## Summary PraisonAI's documented Python `AgentTeam.launch()` / `Agents.launch()` HTTP server starts externally reachable agent invocation endpoints without any authentication… | ||
| CVE-2026-24611 | Cri | 0.59 | 9.1 | 0.00 | Jun 17, 2026 | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. | ||
| CVE-2026-48881 | Cri | 0.59 | 9.1 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. | ||
| CVE-2026-45550 | Cri | 0.59 | 9.1 | 0.00 | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group,… | ||
| CVE-2026-42682 | Cri | 0.59 | 9.1 | 0.00 | Jun 1, 2026 | Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6. |
- risk 0.59cvss 9.1epss 0.00
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10.
- risk 0.59cvss 9.1epss 0.00
The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary…
- risk 0.59cvss —epss 0.00
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.
- risk 0.59cvss 9.1epss 0.01
Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an…
- risk 0.59cvss 9.1epss 0.01
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.59cvss 9.1epss 0.00
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on…
- risk 0.59cvss 9.1epss 0.00
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
- risk 0.59cvss 9.1epss 0.00
Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
- risk 0.59cvss 9.1epss 0.01
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart…
- risk 0.59cvss 9.1epss 0.01
Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client…
- risk 0.59cvss 9.1epss 0.01
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
- risk 0.59cvss 9.1epss 0.00
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and…
- risk 0.59cvss 9.1epss 0.01
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via…
- risk 0.59cvss 9.1epss 0.01
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for…
- risk 0.59cvss —epss —
# AgentOS remains unauthenticated after GHSA-pm96 patched version and allows remote agent invocation ## Summary PraisonAI's `AgentOS` FastAPI deployment surface remains unauthenticated in current main and in releases after the published patched version for…
- risk 0.59cvss —epss —
# PraisonAI `AgentTeam.launch()` exposes unauthenticated remote agent invocation endpoints ## Summary PraisonAI's documented Python `AgentTeam.launch()` / `Agents.launch()` HTTP server starts externally reachable agent invocation endpoints without any authentication…
- risk 0.59cvss 9.1epss 0.00
Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.
- risk 0.59cvss 9.1epss 0.00
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
- risk 0.59cvss 9.1epss 0.00
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group,…
- risk 0.59cvss 9.1epss 0.00
Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.