VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,117)

page 4 of 506
  • CVE-2026-12647CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12646CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12645CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-82923CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of…

  • CVE-2026-84238CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

  • CVE-2026-18431CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses…

  • CVE-2026-73665CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.00

    FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces…

  • CVE-2026-63300CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance…

  • CVE-2026-19656CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code…

  • CVE-2026-62830CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-48085CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional…

  • CVE-2026-28005CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

  • CVE-2026-68979CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but…

  • CVE-2026-16300CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.01

    The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

  • CVE-2026-64746CriJul 27, 2026
    risk 0.64cvss 9.8epss 0.01

    An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.

  • CVE-2026-45552CriJun 10, 2026
    risk 0.64cvss 9.9epss 0.00

    Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter,…

  • CVE-2026-45632CriMay 29, 2026
    risk 0.64cvss 9.9epss 0.00

    Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to other organizations if they know the…

  • CVE-2026-8495CriMay 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.

  • CVE-2026-6510CriMay 14, 2026
    risk 0.64cvss 9.8epss 0.01

    The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This makes it possible for…

  • CVE-2026-26083CriMay 12, 2026
    risk 0.64cvss 9.8epss 0.01

    A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions,…