CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (10,110)
page 498 of 506| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-58377 | Hig | 0.00 | 8.1 | 0.00 | Jun 30, 2026 | JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController… | ||
| CVE-2026-58373 | Med | 0.00 | 4.3 | 0.00 | Jun 30, 2026 | CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the… | ||
| CVE-2026-58176 | Med | 0.00 | 6.5 | 0.00 | Jun 30, 2026 | RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the controller declares no class-level or method-level authorization annotation, so the endpoints are gated… | ||
| CVE-2026-58165 | Hig | 0.00 | 8.8 | 0.00 | Jun 30, 2026 | OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because… | ||
| CVE-2026-12349 | Med | 0.00 | 5.3 | 0.00 | Jun 30, 2026 | The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX… | ||
| CVE-2026-57340 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions. | ||
| CVE-2026-57339 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions. | ||
| CVE-2026-57335 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions. | ||
| CVE-2026-57334 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | ||
| CVE-2026-57332 | Hig | 0.00 | 7.1 | 0.00 | Jun 29, 2026 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. | ||
| CVE-2026-57327 | Med | 0.00 | 6.3 | 0.00 | Jun 29, 2026 | Subscriber Broken Access Control in MainWP <= 6.1.1 versions. | ||
| CVE-2025-2902 | Hig | 0.00 | 8.3 | 0.00 | Jun 29, 2026 | Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi… | ||
| CVE-2026-13537 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used. | ||
| CVE-2026-9233 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-3462 | Med | 0.00 | 6.5 | 0.00 | Jun 27, 2026 | The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with… | ||
| CVE-2026-12471 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | ||
| CVE-2026-12432 | Med | 0.00 | 5.3 | 0.01 | Jun 27, 2026 | The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying… | ||
| CVE-2026-11773 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-12404 | Med | 0.00 | 5.3 | 0.00 | Jun 27, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible… | ||
| CVE-2026-55838 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls… |
- risk 0.00cvss 8.1epss 0.00
JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController…
- risk 0.00cvss 4.3epss 0.00
CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the…
- risk 0.00cvss 6.5epss 0.00
RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the controller declares no class-level or method-level authorization annotation, so the endpoints are gated…
- risk 0.00cvss 8.8epss 0.00
OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because…
- risk 0.00cvss 5.3epss 0.00
The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX…
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
- risk 0.00cvss 7.1epss 0.00
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
- risk 0.00cvss 6.3epss 0.00
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
- risk 0.00cvss 8.3epss 0.00
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.
- risk 0.00cvss 4.3epss 0.00
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.00cvss 6.5epss 0.00
The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with…
- risk 0.00cvss 4.3epss 0.00
The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
- risk 0.00cvss 5.3epss 0.01
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying…
- risk 0.00cvss 4.3epss 0.00
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.00cvss 5.3epss 0.00
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible…
- risk 0.00cvss 4.3epss 0.00
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls…