VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 404 of 464
  • CVE-2026-64664MedAug 6, 2026
    risk 0.21cvss 4.3epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having…

  • CVE-2026-70618MedAug 5, 2026
    risk 0.21cvss 4.3epss 0.00

    Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification.…

  • CVE-2026-70484MedAug 4, 2026
    risk 0.21cvss 4.3epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permission that the direct…

  • CVE-2026-67616MedAug 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts…

  • CVE-2026-67344MedAug 1, 2026
    risk 0.21cvss 4.3epss 0.00

    ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocumentType. An authenticated user with only…

  • CVE-2026-67529MedJul 30, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _links.workPackage.href through associated_resource in modules/costs/lib/api/v3/time_entries/time_entry_…

  • CVE-2026-12955MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in…

  • CVE-2026-59227MedJul 9, 2026
    risk 0.21cvss 4.3epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required only a verified account and did not enforce the global image-edit switch or the per-user image-generation permission, allowing a…

  • CVE-2026-59217MedJul 9, 2026
    risk 0.21cvss 4.3epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded files to a target knowledge base without applying the write-access check used by…

  • CVE-2026-55542MedJul 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the…

  • CVE-2026-14793MedJul 6, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/controllers/GlobalsController.php of the component reorder-sets Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely.…

  • CVE-2026-27783MedJul 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.

  • CVE-2026-25714MedJul 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.

  • CVE-2026-11364MedJun 27, 2026
    risk 0.21cvss 4.3epss 0.00

    The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. This is due to a missing capability check and missing nonce verification in the __invoke() methods of…

  • CVE-2026-56385MedJun 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing an authenticated low-privileged user to…

  • CVE-2026-56384MedJun 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive preview HTML containing a signed fallback…

  • CVE-2026-49288MedJun 19, 2026
    risk 0.21cvss 4.3epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other…

  • CVE-2026-9013MedJun 19, 2026
    risk 0.21cvss 4.3epss 0.00

    The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the bogo_rest_create_post_translation. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the raw…

  • CVE-2026-12515MedJun 17, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were…

  • CVE-2026-0057LowJun 17, 2026
    risk 0.21cvss 3.3epss 0.00

    In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…