CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,259)
page 453 of 463| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-12432 | Med | 0.00 | 5.3 | 0.01 | Jun 27, 2026 | The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying… | ||
| CVE-2026-11773 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-12404 | Med | 0.00 | 5.3 | 0.00 | Jun 27, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible… | ||
| CVE-2026-55838 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls… | ||
| CVE-2026-55189 | Hig | 0.00 | 7.7 | 0.00 | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP… | ||
| CVE-2026-55188 | Hig | 0.00 | 8.2 | 0.00 | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request… | ||
| CVE-2026-49991 | Hig | 0.00 | 8.6 | 0.00 | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users'… | ||
| CVE-2026-47193 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1. | ||
| CVE-2026-44734 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and… | ||
| CVE-2026-57518 | Hig | 0.00 | 8.8 | 0.00 | Jun 26, 2026 | Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in… | ||
| CVE-2026-57661 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions. | ||
| CVE-2026-57660 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions. | ||
| CVE-2026-57654 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions. | ||
| CVE-2026-57649 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions. | ||
| CVE-2026-57648 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Contributor Broken Access Control in Nelio Content <= 4.3.4 versions. | ||
| CVE-2026-57645 | Hig | 0.00 | 8.1 | 0.00 | Jun 26, 2026 | newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions. | ||
| CVE-2026-57640 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions. | ||
| CVE-2026-57632 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. | ||
| CVE-2026-57622 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in WPCafe <= 3.0.14 versions. | ||
| CVE-2026-57430 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions. |
- risk 0.00cvss 5.3epss 0.01
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying…
- risk 0.00cvss 4.3epss 0.00
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.00cvss 5.3epss 0.00
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible…
- risk 0.00cvss 4.3epss 0.00
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls…
- risk 0.00cvss 7.7epss 0.00
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP…
- risk 0.00cvss 8.2epss 0.00
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request…
- risk 0.00cvss 8.6epss 0.00
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users'…
- risk 0.00cvss 7.5epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.
- risk 0.00cvss 6.5epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and…
- risk 0.00cvss 8.8epss 0.00
Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in…
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
- risk 0.00cvss 6.5epss 0.00
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
- risk 0.00cvss 8.1epss 0.00
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.