VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,110)

page 498 of 506
  • CVE-2026-58377HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.00

    JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController…

  • CVE-2026-58373MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the…

  • CVE-2026-58176MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the controller declares no class-level or method-level authorization annotation, so the endpoints are gated…

  • CVE-2026-58165HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because…

  • CVE-2026-12349MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX…

  • CVE-2026-57340MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.

  • CVE-2026-57339MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.

  • CVE-2026-57335MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.

  • CVE-2026-57334MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

  • CVE-2026-57332HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.

  • CVE-2026-57327MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    Subscriber Broken Access Control in MainWP <= 6.1.1 versions.

  • CVE-2025-2902HigJun 29, 2026
    risk 0.00cvss 8.3epss 0.00

    Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi…

  • CVE-2026-13537MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.

  • CVE-2026-9233MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-3462MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.00

    The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with…

  • CVE-2026-12471MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

  • CVE-2026-12432MedJun 27, 2026
    risk 0.00cvss 5.3epss 0.01

    The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying…

  • CVE-2026-11773MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-12404MedJun 27, 2026
    risk 0.00cvss 5.3epss 0.00

    The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible…

  • CVE-2026-55838MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls…