CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (10,113)
page 3 of 506| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-30416 | Cri | 0.65 | 10.0 | 0.00 | Feb 20, 2026 | Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. | ||
| CVE-2025-45854 | Cri | 0.65 | 10.0 | 0.03 | Jun 3, 2025 | /server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams. | ||
| CVE-2025-26853 | Cri | 0.65 | 10.0 | 0.00 | Mar 20, 2025 | DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema. | ||
| CVE-2025-22612 | Cri | 0.65 | 10.0 | 0.01 | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in plain text. If the server… | ||
| CVE-2025-22609 | Cri | 0.65 | 10.0 | 0.01 | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to his own server. If the server… | ||
| CVE-2024-52416 | Cri | 0.65 | 10.0 | 0.00 | Nov 16, 2024 | Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through <= 2.2. | ||
| CVE-2024-9234 | Cri | 0.65 | 9.8 | 0.10 | Oct 11, 2024 | The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API… | ||
| CVE-2024-6500 | Cri | 0.65 | 10.0 | 0.01 | Aug 17, 2024 | The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as… | ||
| CVE-2024-6071 | Cri | 0.65 | 10.0 | 0.01 | Jun 27, 2024 | PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server. | ||
| CVE-2024-33566 | Cri | 0.65 | 10.0 | 0.01 | Apr 29, 2024 | Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4. | ||
| CVE-2022-1574 | Cri | 0.65 | 9.8 | 0.12 | Jun 27, 2022 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server | ||
| CVE-2026-86591 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2026 | The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The… | ||
| CVE-2026-20324 | Cri | 0.64 | 9.9 | 0.00 | Sep 16, 2026 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has… | ||
| CVE-2026-14349 | Cri | 0.64 | 9.8 | 0.00 | Sep 16, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-73807 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2026 | The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions. | ||
| CVE-2026-75030 | Cri | 0.64 | 9.8 | 0.01 | Sep 14, 2026 | Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0… | ||
| CVE-2026-72709 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2026 | SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can… | ||
| CVE-2026-41871 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2026 | Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23,… | ||
| CVE-2026-87534 | Cri | 0.64 | 9.8 | 0.00 | Sep 9, 2026 | Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) | ||
| CVE-2026-83941 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network. |
- risk 0.65cvss 10.0epss 0.00
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
- risk 0.65cvss 10.0epss 0.03
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
- risk 0.65cvss 10.0epss 0.00
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
- risk 0.65cvss 10.0epss 0.01
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in plain text. If the server…
- risk 0.65cvss 10.0epss 0.01
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to his own server. If the server…
- risk 0.65cvss 10.0epss 0.00
Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through <= 2.2.
- risk 0.65cvss 9.8epss 0.10
The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API…
- risk 0.65cvss 10.0epss 0.01
The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as…
- risk 0.65cvss 10.0epss 0.01
PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.
- risk 0.65cvss 10.0epss 0.01
Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.
- risk 0.65cvss 9.8epss 0.12
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
- risk 0.64cvss 9.8epss 0.01
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The…
- risk 0.64cvss 9.9epss 0.00
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has…
- risk 0.64cvss 9.8epss 0.00
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.64cvss 9.8epss 0.01
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
- risk 0.64cvss 9.8epss 0.01
Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0…
- risk 0.64cvss 9.8epss 0.01
SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can…
- risk 0.64cvss 9.8epss 0.01
Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23,…
- risk 0.64cvss 9.8epss 0.00
Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
- risk 0.64cvss 9.9epss 0.01
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.