CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,259)
page 455 of 463| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57923 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings | ||
| CVE-2026-57922 | Low | 0.00 | 3.1 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible | ||
| CVE-2026-57921 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint | ||
| CVE-2026-1869 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the… | ||
| CVE-2026-57521 | Med | 0.00 | 4.3 | 0.00 | Jun 25, 2026 | Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization… | ||
| CVE-2026-57520 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint.… | ||
| CVE-2026-56768 | Hig | 0.00 | 8.8 | 0.00 | Jun 25, 2026 | Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download… | ||
| CVE-2026-56767 | Hig | 0.00 | 8.8 | 0.00 | Jun 25, 2026 | Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify,… | ||
| CVE-2026-54029 | Med | 0.00 | 5.3 | 0.00 | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messages. The validateMessageReq middleware only validates that… | ||
| CVE-2026-54027 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool_resources (e.g., context, execute_code) without verifying ownership or EDIT… | ||
| CVE-2026-48941 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/` | ||
| CVE-2026-57619 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. | ||
| CVE-2026-57429 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | Contributor Broken Access Control in Slim SEO <= 4.6.2 versions. | ||
| CVE-2026-56023 | Med | 0.00 | 5.4 | 0.00 | Jun 25, 2026 | Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. | ||
| CVE-2026-54844 | Hig | 0.00 | 7.5 | 0.00 | Jun 25, 2026 | Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. | ||
| CVE-2026-54842 | Hig | 0.00 | 8.1 | 0.00 | Jun 25, 2026 | Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25. | ||
| CVE-2026-54830 | Hig | 0.00 | 7.5 | 0.00 | Jun 25, 2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. | ||
| CVE-2026-54828 | Hig | 0.00 | 7.5 | 0.00 | Jun 25, 2026 | Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. | ||
| CVE-2026-27366 | Hig | 0.00 | 7.5 | 0.00 | Jun 25, 2026 | Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions. | ||
| CVE-2026-3176 | Low | 0.00 | 3.1 | 0.00 | Jun 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to… |
- risk 0.00cvss 5.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
- risk 0.00cvss 3.1epss 0.00
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
- risk 0.00cvss 6.5epss 0.00
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the…
- risk 0.00cvss 4.3epss 0.00
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization…
- risk 0.00cvss 7.1epss 0.00
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint.…
- risk 0.00cvss 8.8epss 0.00
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download…
- risk 0.00cvss 8.8epss 0.00
Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify,…
- risk 0.00cvss 5.3epss 0.00
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messages. The validateMessageReq middleware only validates that…
- risk 0.00cvss 6.5epss 0.00
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool_resources (e.g., context, execute_code) without verifying ownership or EDIT…
- risk 0.00cvss 6.5epss 0.00
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/`
- risk 0.00cvss 6.5epss 0.00
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
- risk 0.00cvss 5.4epss 0.00
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
- risk 0.00cvss 8.1epss 0.00
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
- risk 0.00cvss 3.1epss 0.00
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to…