VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 452 of 463
  • CVE-2026-58168HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.00

    DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in…

  • CVE-2026-58167MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) user through POST…

  • CVE-2026-58165HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because…

  • CVE-2026-12349MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX…

  • CVE-2026-57498CriJun 29, 2026
    risk 0.00cvss 9.6epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI…

  • CVE-2026-57954MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative…

  • CVE-2026-57952MedJun 29, 2026
    risk 0.00cvss 5.3epss 0.00

    Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in one…

  • CVE-2026-57949MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers…

  • CVE-2026-57946LowJun 29, 2026
    risk 0.00cvss 3.7epss 0.00

    Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed…

  • CVE-2026-57340MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.

  • CVE-2026-57339MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.

  • CVE-2026-57335MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.

  • CVE-2026-57334MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

  • CVE-2026-57332HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.

  • CVE-2026-57327MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    Subscriber Broken Access Control in MainWP <= 6.1.1 versions.

  • CVE-2025-2902HigJun 29, 2026
    risk 0.00cvss 8.3epss 0.00

    Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi…

  • CVE-2026-13537MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.

  • CVE-2026-9233MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-3462MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.00

    The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with…

  • CVE-2026-12471MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…