CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,259)
page 452 of 463| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-58168 | Hig | 0.00 | 8.8 | 0.00 | Jun 30, 2026 | DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in… | ||
| CVE-2026-58167 | Med | 0.00 | 6.5 | 0.00 | Jun 30, 2026 | Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) user through POST… | ||
| CVE-2026-58165 | Hig | 0.00 | 8.8 | 0.00 | Jun 30, 2026 | OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because… | ||
| CVE-2026-12349 | Med | 0.00 | 5.3 | 0.00 | Jun 30, 2026 | The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX… | ||
| CVE-2026-57498 | Cri | 0.00 | 9.6 | 0.00 | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI… | ||
| CVE-2026-57954 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative… | ||
| CVE-2026-57952 | Med | 0.00 | 5.3 | 0.00 | Jun 29, 2026 | Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in one… | ||
| CVE-2026-57949 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers… | ||
| CVE-2026-57946 | Low | 0.00 | 3.7 | 0.00 | Jun 29, 2026 | Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed… | ||
| CVE-2026-57340 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions. | ||
| CVE-2026-57339 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions. | ||
| CVE-2026-57335 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions. | ||
| CVE-2026-57334 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | ||
| CVE-2026-57332 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. | ||
| CVE-2026-57327 | Med | 0.00 | 6.3 | 0.00 | Jun 29, 2026 | Subscriber Broken Access Control in MainWP <= 6.1.1 versions. | ||
| CVE-2025-2902 | Hig | 0.00 | 8.3 | 0.00 | Jun 29, 2026 | Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi… | ||
| CVE-2026-13537 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used. | ||
| CVE-2026-9233 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-3462 | Med | 0.00 | 6.5 | 0.00 | Jun 27, 2026 | The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with… | ||
| CVE-2026-12471 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… |
- risk 0.00cvss 8.8epss 0.00
DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in…
- risk 0.00cvss 6.5epss 0.00
Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) user through POST…
- risk 0.00cvss 8.8epss 0.00
OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because…
- risk 0.00cvss 5.3epss 0.00
The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX…
- risk 0.00cvss 9.6epss 0.00
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI…
- risk 0.00cvss 4.3epss 0.00
Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative…
- risk 0.00cvss 5.3epss 0.00
Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in one…
- risk 0.00cvss 6.5epss 0.00
ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers…
- risk 0.00cvss 3.7epss 0.00
Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed…
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
- risk 0.00cvss 7.1epss 0.00
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
- risk 0.00cvss 6.3epss 0.00
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
- risk 0.00cvss 8.3epss 0.00
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.
- risk 0.00cvss 4.3epss 0.00
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.00cvss 6.5epss 0.00
The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with…
- risk 0.00cvss 4.3epss 0.00
The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…