VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,110)

page 499 of 506
  • CVE-2026-55189HigJun 26, 2026
    risk 0.00cvss 7.7epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP…

  • CVE-2026-55188HigJun 26, 2026
    risk 0.00cvss 8.2epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request…

  • CVE-2026-49991HigJun 26, 2026
    risk 0.00cvss 8.6epss 0.00

    RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users'…

  • CVE-2026-47193HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.

  • CVE-2026-44734MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and…

  • CVE-2026-57661MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.

  • CVE-2026-57660MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.

  • CVE-2026-57654MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

  • CVE-2026-57649MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.

  • CVE-2026-57648MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.

  • CVE-2026-57645HigJun 26, 2026
    risk 0.00cvss 8.1epss 0.00

    newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

  • CVE-2026-57632MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.

  • CVE-2026-57622MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.

  • CVE-2026-57430MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.

  • CVE-2026-57324MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.

  • CVE-2026-57323MedJun 26, 2026
    risk 0.00cvss 5.8epss 0.00

    Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.

  • CVE-2026-56063HigJun 26, 2026
    risk 0.00cvss 8.3epss 0.00

    Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.

  • CVE-2026-56061HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.

  • CVE-2026-56038HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.

  • CVE-2026-56025HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.