CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,439)
page 308 of 472| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-79041 | Med | 0.28 | 4.3 | — | Aug 25, 2026 | Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2026-75908 | Med | 0.28 | 4.3 | — | Aug 25, 2026 | The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | ||
| CVE-2026-78467 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2026 | The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an… | ||
| CVE-2026-75930 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2026 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible… | ||
| CVE-2026-19801 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2026 | The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to… | ||
| CVE-2026-14853 | Med | 0.28 | 4.3 | 0.00 | Aug 23, 2026 | The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products. | ||
| CVE-2026-76074 | Med | 0.28 | 4.3 | 0.00 | Aug 22, 2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is… | ||
| CVE-2026-76057 | Med | 0.28 | 4.3 | 0.00 | Aug 22, 2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is… | ||
| CVE-2026-77391 | Med | 0.28 | 4.3 | 0.00 | Aug 21, 2026 | A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the… | ||
| CVE-2026-76398 | Med | 0.28 | 4.3 | 0.00 | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI… | ||
| CVE-2026-76360 | Med | 0.28 | 4.3 | 0.00 | Aug 19, 2026 | In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users. The vulnerability is a missing authorization check, where the… | ||
| CVE-2026-59992 | Med | 0.28 | 5.4 | 0.00 | Aug 19, 2026 | Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete… | ||
| CVE-2026-76209 | Med | 0.28 | 4.3 | 0.00 | Aug 19, 2026 | phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing attackers to create user accounts when registration is disabled. Attackers can bypass the registration restriction by submitting requests to POST /api/register or… | ||
| CVE-2026-76032 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the result with no authorization step, whereas the… | ||
| CVE-2026-74006 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | ||
| CVE-2026-74003 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | ||
| CVE-2026-75832 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/ scope on the account's raw super-admin ACL… | ||
| CVE-2026-75151 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. | ||
| CVE-2026-75046 | Med | 0.28 | 4.3 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | ||
| CVE-2026-55704 | Med | 0.28 | 4.3 | 0.00 | Aug 17, 2026 | Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, could still receive shared-draft entries through the group posts and group… |
- risk 0.28cvss 4.3epss —
Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)
- risk 0.28cvss 4.3epss —
The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
- risk 0.28cvss 4.3epss 0.00
The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an…
- risk 0.28cvss 4.3epss 0.00
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible…
- risk 0.28cvss 4.3epss 0.00
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to…
- risk 0.28cvss 4.3epss 0.00
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
- risk 0.28cvss 4.3epss 0.00
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is…
- risk 0.28cvss 4.3epss 0.00
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is…
- risk 0.28cvss 4.3epss 0.00
A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the…
- risk 0.28cvss 4.3epss 0.00
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI…
- risk 0.28cvss 4.3epss 0.00
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users. The vulnerability is a missing authorization check, where the…
- risk 0.28cvss 5.4epss 0.00
Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete…
- risk 0.28cvss 4.3epss 0.00
phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing attackers to create user accounts when registration is disabled. Attackers can bypass the registration restriction by submitting requests to POST /api/register or…
- risk 0.28cvss 4.3epss 0.00
Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the result with no authorization step, whereas the…
- risk 0.28cvss 4.3epss 0.00
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
- risk 0.28cvss 4.3epss 0.00
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
- risk 0.28cvss 4.3epss 0.00
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/ scope on the account's raw super-admin ACL…
- risk 0.28cvss 4.3epss 0.00
A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
- risk 0.28cvss 4.3epss 0.00
Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, could still receive shared-draft entries through the group posts and group…