CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,267)
page 439 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-27399 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. | ||
| CVE-2026-27392 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Contributor Broken Access Control in uListing <= 2.2.0 versions. | ||
| CVE-2026-27391 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in uListing <= 2.2.0 versions. | ||
| CVE-2026-27377 | Med | 0.00 | 6.7 | 0.00 | Jul 23, 2026 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | ||
| CVE-2026-27355 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. | ||
| CVE-2026-25466 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. | ||
| CVE-2026-25427 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in eRoom <= 1.7.1 versions. | ||
| CVE-2026-25424 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | ||
| CVE-2026-15827 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12.… | ||
| CVE-2026-15015 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | ||
| CVE-2026-59677 | Med | 0.00 | — | 0.00 | Jul 23, 2026 | A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10. | ||
| CVE-2026-12082 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data. | ||
| CVE-2026-7328 | Med | 0.00 | — | 0.00 | Jul 22, 2026 | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The… | ||
| CVE-2026-65011 | Med | 0.00 | 4.3 | 0.00 | Jul 22, 2026 | Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create… | ||
| CVE-2026-63262 | Med | 0.00 | 4.3 | 0.00 | Jul 22, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control. | ||
| CVE-2026-63143 | Med | 0.00 | 4.3 | 0.00 | Jul 21, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the… | ||
| CVE-2026-60953 | Hig | 0.00 | 8.1 | 0.00 | Jul 21, 2026 | Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access… | ||
| CVE-2026-60712 | Med | 0.00 | 6.5 | 0.00 | Jul 21, 2026 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel… | ||
| CVE-2026-65055 | Med | 0.00 | 5.3 | 0.00 | Jul 21, 2026 | Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data API endpoints on UserStory, Task, Issue,… | ||
| CVE-2026-63092 | Med | 0.00 | 4.3 | 0.00 | Jul 21, 2026 | kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The… |
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in uListing <= 2.2.0 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
- risk 0.00cvss 6.7epss 0.00
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
- risk 0.00cvss 5.3epss 0.00
The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12.…
- risk 0.00cvss 9.8epss 0.00
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
- risk 0.00cvss —epss 0.00
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.
- risk 0.00cvss 7.5epss 0.00
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.
- risk 0.00cvss —epss 0.00
Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The…
- risk 0.00cvss 4.3epss 0.00
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create…
- risk 0.00cvss 4.3epss 0.00
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.
- risk 0.00cvss 4.3epss 0.00
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the…
- risk 0.00cvss 8.1epss 0.00
Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access…
- risk 0.00cvss 6.5epss 0.00
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel…
- risk 0.00cvss 5.3epss 0.00
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data API endpoints on UserStory, Task, Issue,…
- risk 0.00cvss 4.3epss 0.00
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The…