VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,043)

page 491 of 503
  • CVE-2026-59800CriJul 7, 2026
    risk 0.00cvss 9.8epss 0.02

    9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied). The sudoPassword field from the request…

  • CVE-2026-11340HigJul 7, 2026
    risk 0.00cvss 8.3epss 0.00

    Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: before release.Master.1107.

  • CVE-2026-8377HigJul 7, 2026
    risk 0.00cvss 8.2epss 0.00

    Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control System (GKS): before Version 2.

  • CVE-2026-34048CriJul 7, 2026
    risk 0.00cvss 9.9epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect…

  • CVE-2026-53647MedJul 7, 2026
    risk 0.00cvss —epss 0.01

    FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without authentication. Any caller with a valid API key can retrieve all custom configuration parameters…

  • CVE-2026-53643HigJul 6, 2026
    risk 0.00cvss —epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API endpoints. The root cause is a combination of the `can_always_access` module flag (which grants all…

  • CVE-2026-53640LowJul 6, 2026
    risk 0.00cvss —epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that lack permission checks. While sibling write endpoints correctly enforce fine-grained permissions,…

  • CVE-2026-34050MedJul 6, 2026
    risk 0.00cvss 6.5epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in its mount method, allowing non-admin users to access the Updates settings page…

  • CVE-2026-14800MedJul 6, 2026
    risk 0.00cvss 4.3epss 0.00

    A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made…

  • CVE-2026-6509HigJul 5, 2026
    risk 0.00cvss 7.8epss 0.00

    Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from <=0.6.3 before 0.6.6.

  • CVE-2026-14460HigJul 3, 2026
    risk 0.00cvss 8.8epss 0.00

    Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5.

  • CVE-2026-11398MedJul 3, 2026
    risk 0.00cvss 5.3epss 0.01

    The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

  • CVE-2026-9230MedJul 3, 2026
    risk 0.00cvss 4.3epss 0.00

    The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-12557MedJul 3, 2026
    risk 0.00cvss 5.3epss 0.00

    The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…

  • CVE-2026-12729MedJul 3, 2026
    risk 0.00cvss 4.3epss 0.00

    The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the…

  • CVE-2026-59097MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.01

    Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can…

  • CVE-2026-57760MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.

  • CVE-2026-57750MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.

  • CVE-2026-57746HigJul 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Subscriber Broken Access Control in Booked <= 3.0.0 versions.

  • CVE-2026-57731MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Broken Access Control in Flatsome <= 3.20.5 versions.