CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,438)
page 311 of 472| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57300 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access. | ||
| CVE-2026-57299 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata. | ||
| CVE-2026-57297 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key. | ||
| CVE-2026-57293 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins. | ||
| CVE-2026-57286 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata. | ||
| CVE-2026-57285 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration. | ||
| CVE-2026-9619 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated… | ||
| CVE-2026-9616 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | ||
| CVE-2026-9184 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX function in versions up to, and including, 2.2. The handler only verifies the 'lb24' nonce (which is… | ||
| CVE-2026-8688 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | ||
| CVE-2026-8614 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings() function in versions up to, and including, 1.1.2. This makes it possible for… | ||
| CVE-2026-54016 | Med | 0.28 | 4.3 | 0.00 | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the builtin search_knowledge_files tool. When native function calling is enabled and the… | ||
| CVE-2026-56696 | Med | 0.28 | 5.4 | 0.00 | Jun 23, 2026 | OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and… | ||
| CVE-2026-3640 | Med | 0.28 | 5.3 | 0.01 | Jun 19, 2026 | The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin registers a REST API webhook endpoint at /wp-json/strabl/webhook/order with a permission_callback of __return_true, which allows… | ||
| CVE-2026-10779 | Med | 0.28 | 4.3 | 0.00 | Jun 19, 2026 | The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler… | ||
| CVE-2026-9199 | Med | 0.28 | 4.3 | 0.00 | Jun 18, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform… | ||
| CVE-2026-40723 | Med | 0.28 | 4.3 | 0.00 | Jun 17, 2026 | Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions. | ||
| CVE-2026-24610 | Med | 0.28 | 4.3 | 0.00 | Jun 17, 2026 | Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions. | ||
| CVE-2026-24575 | Med | 0.28 | 4.3 | 0.00 | Jun 17, 2026 | Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions. | ||
| CVE-2024-37496 | Med | 0.28 | 4.3 | 0.00 | Jun 17, 2026 | Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7. |
- risk 0.28cvss 4.3epss 0.00
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.
- risk 0.28cvss 4.3epss 0.00
Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.
- risk 0.28cvss 4.3epss 0.00
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.
- risk 0.28cvss 4.3epss 0.00
An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins.
- risk 0.28cvss 4.3epss 0.00
A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.
- risk 0.28cvss 4.3epss 0.00
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.
- risk 0.28cvss 4.3epss 0.00
The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…
- risk 0.28cvss 4.3epss 0.00
The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
- risk 0.28cvss 4.3epss 0.00
The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX function in versions up to, and including, 2.2. The handler only verifies the 'lb24' nonce (which is…
- risk 0.28cvss 4.3epss 0.00
The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
- risk 0.28cvss 4.3epss 0.00
The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings() function in versions up to, and including, 1.1.2. This makes it possible for…
- risk 0.28cvss 4.3epss 0.00
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the builtin search_knowledge_files tool. When native function calling is enabled and the…
- risk 0.28cvss 5.4epss 0.00
OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and…
- risk 0.28cvss 5.3epss 0.01
The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin registers a REST API webhook endpoint at /wp-json/strabl/webhook/order with a permission_callback of __return_true, which allows…
- risk 0.28cvss 4.3epss 0.00
The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler…
- risk 0.28cvss 4.3epss 0.00
The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform…
- risk 0.28cvss 4.3epss 0.00
Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.
- risk 0.28cvss 4.3epss 0.00
Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions.
- risk 0.28cvss 4.3epss 0.00
Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.
- risk 0.28cvss 4.3epss 0.00
Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7.