VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,438)

page 311 of 472
  • CVE-2026-57300MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.

  • CVE-2026-57299MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.

  • CVE-2026-57297MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.

  • CVE-2026-57293MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-57286MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.

  • CVE-2026-57285MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.

  • CVE-2026-9619MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…

  • CVE-2026-9616MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…

  • CVE-2026-9184MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX function in versions up to, and including, 2.2. The handler only verifies the 'lb24' nonce (which is…

  • CVE-2026-8688MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…

  • CVE-2026-8614MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings() function in versions up to, and including, 1.1.2. This makes it possible for…

  • CVE-2026-54016MedJun 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the builtin search_knowledge_files tool. When native function calling is enabled and the…

  • CVE-2026-56696MedJun 23, 2026
    risk 0.28cvss 5.4epss 0.00

    OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to write attacker-controlled Markdown into project context files. Admitted remote attackers can inject malicious content into .openharness/issue.md and…

  • CVE-2026-3640MedJun 19, 2026
    risk 0.28cvss 5.3epss 0.01

    The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin registers a REST API webhook endpoint at /wp-json/strabl/webhook/order with a permission_callback of __return_true, which allows…

  • CVE-2026-10779MedJun 19, 2026
    risk 0.28cvss 4.3epss 0.00

    The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler…

  • CVE-2026-9199MedJun 18, 2026
    risk 0.28cvss 4.3epss 0.00

    The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform…

  • CVE-2026-40723MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.

  • CVE-2026-24610MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions.

  • CVE-2026-24575MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.

  • CVE-2024-37496MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7.