VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 455 of 463
  • CVE-2026-57923MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

  • CVE-2026-57922LowJun 26, 2026
    risk 0.00cvss 3.1epss 0.00

    In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

  • CVE-2026-57921MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

  • CVE-2026-1869MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the…

  • CVE-2026-57521MedJun 25, 2026
    risk 0.00cvss 4.3epss 0.00

    Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization…

  • CVE-2026-57520HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint.…

  • CVE-2026-56768HigJun 25, 2026
    risk 0.00cvss 8.8epss 0.00

    Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download…

  • CVE-2026-56767HigJun 25, 2026
    risk 0.00cvss 8.8epss 0.00

    Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify,…

  • CVE-2026-54029MedJun 25, 2026
    risk 0.00cvss 5.3epss 0.00

    LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messages. The validateMessageReq middleware only validates that…

  • CVE-2026-54027MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool_resources (e.g., context, execute_code) without verifying ownership or EDIT…

  • CVE-2026-48941MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/`

  • CVE-2026-57619MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

  • CVE-2026-57429MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.

  • CVE-2026-56023MedJun 25, 2026
    risk 0.00cvss 5.4epss 0.00

    Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

  • CVE-2026-54844HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.

  • CVE-2026-54842HigJun 25, 2026
    risk 0.00cvss 8.1epss 0.00

    Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.

  • CVE-2026-54830HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.

  • CVE-2026-54828HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

  • CVE-2026-27366HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.

  • CVE-2026-3176LowJun 25, 2026
    risk 0.00cvss 3.1epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to…