CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,262)
page 42 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-0555 | Hig | 0.54 | 7.8 | 0.02 | Jan 8, 2019 | An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows… | ||
| CVE-2017-13209 | Hig | 0.54 | 7.8 | 0.01 | Jan 12, 2018 | In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a local elevation of privilege… | ||
| CVE-2017-3813 | Hig | 0.54 | 7.8 | 0.02 | Feb 9, 2017 | A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vulnerability is due to insufficient… | ||
| CVE-2026-75051 | Hig | 0.53 | 8.1 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | ||
| CVE-2026-75044 | Hig | 0.53 | 8.1 | 0.00 | Aug 17, 2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | ||
| CVE-2026-16772 | Hig | 0.53 | 8.1 | 0.00 | Aug 14, 2026 | In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role… | ||
| CVE-2026-72665 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security… | ||
| CVE-2026-28186 | Hig | 0.53 | 8.1 | 0.00 | Aug 13, 2026 | Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. | ||
| CVE-2026-66375 | Hig | 0.53 | 8.1 | 0.00 | Aug 12, 2026 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. | ||
| CVE-2026-70340 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-14886 | Hig | 0.53 | 8.2 | 0.00 | Aug 10, 2026 | Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the storage backing of entities belonging to another namespace. This vulnerability… | ||
| CVE-2026-47754 | Cri | 0.53 | 9.3 | 0.00 | Aug 10, 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endpoint that is part of the… | ||
| CVE-2026-18030 | Hig | 0.53 | 8.1 | 0.00 | Aug 10, 2026 | The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and… | ||
| CVE-2026-66708 | Hig | 0.53 | 8.2 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | ||
| CVE-2026-71264 | Hig | 0.53 | 8.2 | 0.00 | Aug 5, 2026 | WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike the /edit endpoint which explicitly checks correctPIN, disclosing the device's general configuration (network, hardware, LED setup) to any unauthenticated… | ||
| CVE-2026-71252 | — | Hig | 0.53 | 8.2 | 0.00 | Aug 5, 2026 | toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while access… | |
| CVE-2026-7520 | Hig | 0.53 | 8.1 | 0.00 | Aug 5, 2026 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated… | ||
| CVE-2026-6627 | Hig | 0.53 | 8.2 | 0.01 | Aug 5, 2026 | The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce verification on the… | ||
| CVE-2026-54418 | Hig | 0.53 | 8.1 | 0.00 | Aug 5, 2026 | Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other… | ||
| CVE-2026-47688 | Hig | 0.53 | 8.2 | 0.00 | Jul 21, 2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the… |
- risk 0.54cvss 7.8epss 0.02
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows…
- risk 0.54cvss 7.8epss 0.01
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a local elevation of privilege…
- risk 0.54cvss 7.8epss 0.02
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vulnerability is due to insufficient…
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
- risk 0.53cvss 8.1epss 0.00
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
- risk 0.53cvss 8.1epss 0.00
In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role…
- risk 0.53cvss 8.1epss 0.00
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security…
- risk 0.53cvss 8.1epss 0.00
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
- risk 0.53cvss 8.1epss 0.00
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
- risk 0.53cvss 8.1epss 0.01
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.2epss 0.00
Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the storage backing of entities belonging to another namespace. This vulnerability…
- risk 0.53cvss 9.3epss 0.00
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endpoint that is part of the…
- risk 0.53cvss 8.1epss 0.00
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and…
- risk 0.53cvss 8.2epss 0.00
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
- risk 0.53cvss 8.2epss 0.00
WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike the /edit endpoint which explicitly checks correctPIN, disclosing the device's general configuration (network, hardware, LED setup) to any unauthenticated…
- risk 0.53cvss 8.2epss 0.00
toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while access…
- risk 0.53cvss 8.1epss 0.00
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated…
- risk 0.53cvss 8.2epss 0.01
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce verification on the…
- risk 0.53cvss 8.1epss 0.00
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other…
- risk 0.53cvss 8.2epss 0.00
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the…