VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,113)

page 3 of 506
  • CVE-2025-30416CriFeb 20, 2026
    risk 0.65cvss 10.0epss 0.00

    Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

  • CVE-2025-45854CriJun 3, 2025
    risk 0.65cvss 10.0epss 0.03

    /server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

  • CVE-2025-26853CriMar 20, 2025
    risk 0.65cvss 10.0epss 0.00

    DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

  • CVE-2025-22612CriJan 24, 2025
    risk 0.65cvss 10.0epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in plain text. If the server…

  • CVE-2025-22609CriJan 24, 2025
    risk 0.65cvss 10.0epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to his own server. If the server…

  • CVE-2024-52416CriNov 16, 2024
    risk 0.65cvss 10.0epss 0.00

    Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through <= 2.2.

  • CVE-2024-9234CriOct 11, 2024
    risk 0.65cvss 9.8epss 0.10

    The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API…

  • CVE-2024-6500CriAug 17, 2024
    risk 0.65cvss 10.0epss 0.01

    The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as…

  • CVE-2024-6071CriJun 27, 2024
    risk 0.65cvss 10.0epss 0.01

    PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.

  • CVE-2024-33566CriApr 29, 2024
    risk 0.65cvss 10.0epss 0.01

    Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.

  • CVE-2022-1574CriJun 27, 2022
    risk 0.65cvss 9.8epss 0.12

    The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server

  • CVE-2026-86591CriSep 19, 2026
    risk 0.64cvss 9.8epss 0.01

    The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The…

  • CVE-2026-20324CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.00

    A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has…

  • CVE-2026-14349CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-73807CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.01

    The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.

  • CVE-2026-75030CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0…

  • CVE-2026-72709CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can…

  • CVE-2026-41871CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23,…

  • CVE-2026-87534CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-83941CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.