CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,267)
page 436 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65433 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||
| CVE-2026-59560 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | ||
| CVE-2026-59557 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | ||
| CVE-2026-59536 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | ||
| CVE-2026-59535 | Hig | 0.00 | 7.3 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. | ||
| CVE-2026-59534 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions. | ||
| CVE-2026-59530 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | ||
| CVE-2026-59529 | Hig | 0.00 | 7.5 | 0.00 | Jul 27, 2026 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | ||
| CVE-2026-13390 | Med | 0.00 | 5.3 | 0.00 | Jul 27, 2026 | The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as… | ||
| CVE-2026-66012 | Cri | 0.00 | 10.0 | 0.00 | Jul 25, 2026 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with… | ||
| CVE-2026-66027 | Hig | 0.00 | 8.3 | 0.00 | Jul 24, 2026 | Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read… | ||
| CVE-2026-16799 | Med | 0.00 | 5.0 | 0.00 | Jul 24, 2026 | Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization… | ||
| CVE-2026-10033 | Hig | 0.00 | 7.3 | 0.00 | Jul 24, 2026 | The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers… | ||
| CVE-2026-12654 | Med | 0.00 | 5.3 | 0.00 | Jul 24, 2026 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | ||
| CVE-2026-12690 | Low | 0.00 | 3.8 | 0.00 | Jul 24, 2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's… | ||
| CVE-2026-12689 | Med | 0.00 | 5.4 | 0.00 | Jul 24, 2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read… | ||
| CVE-2026-11354 | Med | 0.00 | 5.3 | 0.00 | Jul 24, 2026 | The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and… | ||
| CVE-2026-47755 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the… | ||
| CVE-2026-65916 | Hig | 0.00 | 8.1 | 0.00 | Jul 23, 2026 | CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary… | ||
| CVE-2026-65895 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable… |
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
- risk 0.00cvss 7.3epss 0.00
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
- risk 0.00cvss 5.3epss 0.00
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as…
- risk 0.00cvss 10.0epss 0.00
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with…
- risk 0.00cvss 8.3epss 0.00
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read…
- risk 0.00cvss 5.0epss 0.00
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization…
- risk 0.00cvss 7.3epss 0.00
The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers…
- risk 0.00cvss 5.3epss 0.00
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
- risk 0.00cvss 3.8epss 0.00
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's…
- risk 0.00cvss 5.4epss 0.00
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read…
- risk 0.00cvss 5.3epss 0.00
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and…
- risk 0.00cvss 6.5epss 0.00
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the…
- risk 0.00cvss 8.1epss 0.00
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary…
- risk 0.00cvss 8.5epss 0.00
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable…