VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,439)

page 308 of 472
  • CVE-2026-79041MedAug 25, 2026
    risk 0.28cvss 4.3epss

    Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-75908MedAug 25, 2026
    risk 0.28cvss 4.3epss

    The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…

  • CVE-2026-78467MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an…

  • CVE-2026-75930MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible…

  • CVE-2026-19801MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to…

  • CVE-2026-14853MedAug 23, 2026
    risk 0.28cvss 4.3epss 0.00

    The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.

  • CVE-2026-76074MedAug 22, 2026
    risk 0.28cvss 4.3epss 0.00

    The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-76057MedAug 22, 2026
    risk 0.28cvss 4.3epss 0.00

    The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-77391MedAug 21, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the…

  • CVE-2026-76398MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI…

  • CVE-2026-76360MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users. The vulnerability is a missing authorization check, where the…

  • CVE-2026-59992MedAug 19, 2026
    risk 0.28cvss 5.4epss 0.00

    Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete…

  • CVE-2026-76209MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing attackers to create user accounts when registration is disabled. Attackers can bypass the registration restriction by submitting requests to POST /api/register or…

  • CVE-2026-76032MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the result with no authorization step, whereas the…

  • CVE-2026-74006MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

  • CVE-2026-74003MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.

  • CVE-2026-75832MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/ scope on the account's raw super-admin ACL…

  • CVE-2026-75151MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.

  • CVE-2026-75046MedAug 17, 2026
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

  • CVE-2026-55704MedAug 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, could still receive shared-draft entries through the group posts and group…