VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 43 of 464
  • CVE-2026-49291HigJun 19, 2026
    risk 0.53cvss 8.1epss 0.00

    mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only…

  • CVE-2026-49081HigJun 17, 2026
    risk 0.53cvss 8.2epss 0.00

    Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.

  • CVE-2026-40726HigJun 17, 2026
    risk 0.53cvss 8.2epss 0.00

    Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.

  • CVE-2026-49065HigJun 15, 2026
    risk 0.53cvss 8.2epss 0.00

    Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.

  • CVE-2026-42664HigJun 15, 2026
    risk 0.53cvss 8.2epss 0.00

    Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions.

  • CVE-2026-7368HigJun 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any…

  • CVE-2026-33137CriMay 20, 2026
    risk 0.53cvss epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes…

  • CVE-2026-34358HigMay 19, 2026
    risk 0.53cvss 8.1epss 0.00

    CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin controllers enforce permission checks on form display methods but omit equivalent checks on the corresponding write…

  • CVE-2026-39432HigMay 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53.

  • CVE-2026-5944HigApr 28, 2026
    risk 0.53cvss 8.2epss 0.01

    An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. …

  • CVE-2026-40623HigApr 24, 2026
    risk 0.53cvss 8.1epss 0.00

    A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as…

  • CVE-2026-31921HigMar 25, 2026
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2.

  • CVE-2026-26742HigMar 10, 2026
    risk 0.53cvss 8.1epss 0.00

    PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default…

  • CVE-2026-26741HigMar 10, 2026
    risk 0.53cvss 8.1epss 0.00

    PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" state (after landing and before the automatic disarm triggered by the COM_DISARM_LAND parameter), the…

  • CVE-2026-30797HigMar 5, 2026
    risk 0.53cvss 8.1epss 0.00

    Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated…

  • CVE-2025-67977HigFeb 20, 2026
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.8.

  • CVE-2026-26367HigFeb 15, 2026
    risk 0.53cvss 8.1epss 0.00

    eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated low-privileged user (UG_USER) to delete arbitrary user accounts, except for the built-in admin account. The application…

  • CVE-2026-25939CriFeb 9, 2026
    risk 0.53cvss 9.1epss 0.11

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA…

  • CVE-2025-67956HigJan 22, 2026
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.6.

  • CVE-2025-64729HigJan 16, 2026
    risk 0.53cvss 8.1epss 0.00

    The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.