VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,438)

page 310 of 472
  • CVE-2026-58244MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation…

  • CVE-2026-72918MedAug 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an authenticated user to write arbitrary notification bodies…

  • CVE-2026-16965MedAug 9, 2026
    risk 0.28cvss 4.3epss 0.00

    The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's…

  • CVE-2026-18276MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls…

  • CVE-2026-66678MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.

  • CVE-2026-15246MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid…

  • CVE-2025-9266MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2026-70445MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70438MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70436MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with…

  • CVE-2026-70433MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-7105MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including, 1.5.1. This makes it possible for authenticated attackers, with…

  • CVE-2026-18819MedAug 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-70481MedAug 4, 2026
    risk 0.28cvss 5.4epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message.…

  • CVE-2026-16546MedAug 4, 2026
    risk 0.28cvss 4.3epss 0.00

    The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary…

  • CVE-2026-16056MedAug 4, 2026
    risk 0.28cvss 4.3epss 0.00

    The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

  • CVE-2026-16035MedAug 4, 2026
    risk 0.28cvss 4.3epss 0.00

    The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients…

  • CVE-2026-16289MedAug 3, 2026
    risk 0.28cvss 4.3epss 0.00

    The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any…

  • CVE-2026-16042MedAug 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.

  • CVE-2026-10782MedAug 1, 2026
    risk 0.28cvss 4.3epss 0.00

    The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…