VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 453 of 463
  • CVE-2026-12432MedJun 27, 2026
    risk 0.00cvss 5.3epss 0.01

    The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying…

  • CVE-2026-11773MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-12404MedJun 27, 2026
    risk 0.00cvss 5.3epss 0.00

    The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible…

  • CVE-2026-55838MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls…

  • CVE-2026-55189HigJun 26, 2026
    risk 0.00cvss 7.7epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP…

  • CVE-2026-55188HigJun 26, 2026
    risk 0.00cvss 8.2epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request…

  • CVE-2026-49991HigJun 26, 2026
    risk 0.00cvss 8.6epss 0.00

    RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users'…

  • CVE-2026-47193HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.

  • CVE-2026-44734MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and…

  • CVE-2026-57518HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in…

  • CVE-2026-57661MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.

  • CVE-2026-57660MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.

  • CVE-2026-57654MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

  • CVE-2026-57649MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.

  • CVE-2026-57648MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.

  • CVE-2026-57645HigJun 26, 2026
    risk 0.00cvss 8.1epss 0.00

    newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

  • CVE-2026-57640MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.

  • CVE-2026-57632MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.

  • CVE-2026-57622MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.

  • CVE-2026-57430MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.