VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 441 of 464
  • CVE-2026-12723MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment…

  • CVE-2026-11868MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

  • CVE-2026-16216MedJul 19, 2026
    risk 0.00cvss 4.3epss 0.00

    A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to…

  • CVE-2026-16215MedJul 19, 2026
    risk 0.00cvss 6.5epss 0.00

    A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possible to be carried out remotely. The exploit…

  • CVE-2026-16197MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization. The attack…

  • CVE-2026-16123MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation causes missing authorization. The attack can…

  • CVE-2026-16081MedJul 18, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly…

  • CVE-2026-12694CriJul 17, 2026
    risk 0.00cvss 9.1epss 0.00

    Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

  • CVE-2026-63100MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show and update actions in the Settings::HostingsController, where the…

  • CVE-2026-15783MedJul 17, 2026
    risk 0.00cvss epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch…

  • CVE-2026-12715HigJul 17, 2026
    risk 0.00cvss epss 0.00

    Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on…

  • CVE-2026-16017MedJul 17, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the component cron Chat Tool. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has…

  • CVE-2026-11575HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces…

  • CVE-2026-15349MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

  • CVE-2026-13765HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the…

  • CVE-2026-8616MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to…

  • CVE-2026-62235MedJul 17, 2026
    risk 0.00cvss 6.3epss 0.00

    Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access…

  • CVE-2026-62233HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-admin accounts or strip 2FA from…

  • CVE-2026-62232HigJul 17, 2026
    risk 0.00cvss 7.4epss 0.00

    Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim's password can call this task…

  • CVE-2026-62218HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature…