VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,439)

page 309 of 472
  • CVE-2026-16049MedAug 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance,…

  • CVE-2026-18347MedAug 16, 2026
    risk 0.28cvss 4.3epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

  • CVE-2026-15345MedAug 16, 2026
    risk 0.28cvss 4.3epss 0.00

    The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

  • CVE-2026-16779MedAug 16, 2026
    risk 0.28cvss 4.3epss 0.00

    The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…

  • CVE-2026-13167MedAug 16, 2026
    risk 0.28cvss 4.3epss 0.00

    The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to…

  • CVE-2026-18807MedAug 15, 2026
    risk 0.28cvss 4.3epss 0.00

    The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete…

  • CVE-2026-72671MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create…

  • CVE-2026-50105MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

  • CVE-2026-6821MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request…

  • CVE-2026-4879MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check…

  • CVE-2026-18244MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to view restricted configuration settings due to improper authorization…

  • CVE-2026-70547MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user without repository read permission may access package metadata under specific conditions.

  • CVE-2026-65938MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

  • CVE-2026-73287MedAug 12, 2026
    risk 0.28cvss 5.4epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Action::CreateBucket, allowing authenticated…

  • CVE-2026-66380MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.

  • CVE-2026-66379MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user may view private Puppet module metadata without repository read access.

  • CVE-2026-66378MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

  • CVE-2026-19052MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data…

  • CVE-2026-69113MedAug 11, 2026
    risk 0.28cvss 5.4epss 0.00

    Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on any private video without permission by supplying an arbitrary videoId in the request body. Attackers can inject comments into…

  • CVE-2026-14549MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages.