VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 170 of 475
  • CVE-2017-0896MedJun 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured…

  • CVE-2017-6564MedMay 1, 2017
    risk 0.42cvss 6.5epss 0.01

    On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host…

  • CVE-2026-77128MedAug 25, 2026
    risk 0.41cvss epss 0.00

    The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this…

  • CVE-2026-66689MedAug 13, 2026
    risk 0.41cvss 6.3epss 0.00

    Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions.

  • CVE-2026-73603MedAug 13, 2026
    risk 0.41cvss epss 0.00

    Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API…

  • CVE-2026-63141MedJul 21, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

  • CVE-2026-42651MedJun 15, 2026
    risk 0.41cvss 6.3epss 0.00

    Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions.

  • CVE-2025-68049MedJun 15, 2026
    risk 0.41cvss 6.3epss 0.00

    Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.

  • CVE-2026-10815MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in…

  • CVE-2026-27331MedMay 26, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5.

  • CVE-2026-42776MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7.

  • CVE-2026-40133MedMay 12, 2026
    risk 0.41cvss 6.3epss 0.00

    Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this…

  • CVE-2026-25460MedMar 25, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ave Core: from n/a through <= 2.9.1.

  • CVE-2026-27091MedMar 19, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UiPress lite: from n/a through <= 3.5.09.

  • CVE-2026-3977MedMar 12, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. The manipulation leads to missing authorization. The attack can be initiated remotely. The identifier of the patch is…

  • CVE-2026-28071MedMar 5, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pixfort Core: from n/a through <= 3.2.22.

  • CVE-2026-2819MedFeb 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to missing authorization. The attack may be…

  • CVE-2026-2065MedFeb 6, 2026
    risk 0.41cvss 6.3epss 0.01

    A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Bluetooth Low Energy Interface. Performing a manipulation results in missing authentication. The attack can only be performed from…

  • CVE-2025-65098HigJan 22, 2026
    risk 0.41cvss 7.4epss 0.00

    Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a malicious typebot by clicking "Run", JavaScript executes in their browser and…

  • CVE-2025-15406MedJan 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used.