VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,097)

page 2 of 505
  • CVE-2026-1830CriApr 9, 2026
    risk 0.67cvss 9.8epss 0.08

    The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible…

  • CVE-2015-10143CriJul 25, 2025
    risk 0.67cvss 9.8epss 0.03

    The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the *_ajax_save_options() function in all versions up to 1.4.4 (exclusive). This makes it possible for unauthenticated…

  • CVE-2023-6875CriJan 11, 2024
    risk 0.67cvss 9.8epss 0.90

    The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and…

  • CVE-2020-14944CriJun 22, 2020
    risk 0.67cvss 9.8epss 0.06

    Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile,…

  • CVE-2017-6639CriJun 8, 2017
    risk 0.67cvss 9.8epss 0.35

    A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system. The…

  • CVE-2022-1020CriApr 18, 2022
    risk 0.66cvss 9.8epss 0.26

    The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback…

  • CVE-2022-23642HigFeb 18, 2022
    risk 0.66cvss 8.8epss 0.74

    Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the…

  • CVE-2021-21307HigFeb 11, 2021
    risk 0.66cvss 8.6epss 0.89

    Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or…

  • CVE-2018-10093HigMar 21, 2019
    risk 0.66cvss 8.8epss 0.68

    AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.

  • CVE-2026-101000CriSep 28, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible…

  • CVE-2026-65381CriSep 14, 2026
    risk 0.65cvss 10.0epss 0.00

    A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious app may be able to break out of its sandbox.

  • CVE-2026-81648CriSep 13, 2026
    risk 0.65cvss 10.0epss 0.01

    The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment…

  • CVE-2026-77770CriSep 10, 2026
    risk 0.65cvss 10.0epss 0.00

    The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can…

  • CVE-2026-65667CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-48168CriAug 5, 2026
    risk 0.65cvss 10.0epss 0.01

    PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation.…

  • CVE-2026-66012CriJul 25, 2026
    risk 0.65cvss 10.0epss 0.01

    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with…

  • CVE-2026-58275CriJul 24, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-0092CriJun 17, 2026
    risk 0.65cvss —epss 0.00

    In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-33712CriMay 22, 2026
    risk 0.65cvss 10.0epss 0.00

    Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side…

  • CVE-2026-2031CriMay 15, 2026
    risk 0.65cvss —epss 0.01

    An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted…