VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 181 of 475
  • CVE-2026-69107MedAug 12, 2026
    risk 0.38cvss 5.9epss 0.00

    An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

  • CVE-2026-58237MedAug 11, 2026
    risk 0.38cvss 5.9epss 0.00

    WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform…

  • CVE-2026-72759MedAug 10, 2026
    risk 0.38cvss epss 0.00

    In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record references a deleted conversion, the associated conversion lookup returns None. The previous logic only denied access when the…

  • CVE-2026-58482MedJul 20, 2026
    risk 0.38cvss 5.9epss 0.00

    Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which `ApprovalGate` uses to require explicit human approval…

  • CVE-2026-52714MedJun 16, 2026
    risk 0.38cvss 5.9epss 0.00

    Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.

  • CVE-2026-50026MedJun 12, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

  • CVE-2026-27687MedMar 10, 2026
    risk 0.38cvss 5.8epss 0.00

    Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does not affect integrity and availability.

  • CVE-2026-27686MedMar 10, 2026
    risk 0.38cvss 5.9epss 0.00

    Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially…

  • CVE-2026-3638MedMar 9, 2026
    risk 0.38cvss 5.9epss 0.00

    Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated user to restore deleted users and roles via crafted API requests.

  • CVE-2026-27344MedMar 5, 2026
    risk 0.38cvss 5.9epss 0.00

    Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects inseri core: from n/a through <= 1.0.5.

  • CVE-2025-67970MedFeb 20, 2026
    risk 0.38cvss 5.9epss 0.00

    Missing Authorization vulnerability in vertim Schedula schedula-smart-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schedula: from n/a through <= 1.0.

  • CVE-2026-0829MedFeb 17, 2026
    risk 0.38cvss 5.8epss 0.01

    The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess…

  • CVE-2025-13391MedFeb 11, 2026
    risk 0.38cvss 5.8epss 0.00

    The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'uni_cpo_remove_file' function in all versions up to, and including, 4.9.60. This…

  • CVE-2025-54743MedDec 18, 2025
    risk 0.38cvss 5.8epss 0.00

    Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download After Email: from n/a through 2.1.5-2.1.6.

  • CVE-2025-62642MedOct 17, 2025
    risk 0.38cvss 5.8epss 0.00

    The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account.

  • CVE-2025-11380MedOct 11, 2025
    risk 0.38cvss 5.9epss 0.00

    The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This…

  • CVE-2025-36756MedSep 10, 2025
    risk 0.38cvss epss 0.00

    A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.

  • CVE-2025-54734MedAug 28, 2025
    risk 0.38cvss 5.8epss 0.00

    Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Slider: from n/a through <= 1.1.30.

  • CVE-2025-2246MedAug 27, 2025
    risk 0.38cvss 5.8epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

  • CVE-2025-43008MedMay 13, 2025
    risk 0.38cvss 5.8epss 0.00

    Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.