CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (10,110)
page 499 of 506| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-55189 | Hig | 0.00 | 7.7 | 0.00 | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP… | ||
| CVE-2026-55188 | Hig | 0.00 | 8.2 | 0.00 | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request… | ||
| CVE-2026-49991 | Hig | 0.00 | 8.6 | 0.00 | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users'… | ||
| CVE-2026-47193 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1. | ||
| CVE-2026-44734 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and… | ||
| CVE-2026-57661 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions. | ||
| CVE-2026-57660 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions. | ||
| CVE-2026-57654 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions. | ||
| CVE-2026-57649 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions. | ||
| CVE-2026-57648 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Contributor Broken Access Control in Nelio Content <= 4.3.4 versions. | ||
| CVE-2026-57645 | Hig | 0.00 | 8.1 | 0.00 | Jun 26, 2026 | newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions. | ||
| CVE-2026-57632 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. | ||
| CVE-2026-57622 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in WPCafe <= 3.0.14 versions. | ||
| CVE-2026-57430 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions. | ||
| CVE-2026-57324 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions. | ||
| CVE-2026-57323 | Med | 0.00 | 5.8 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions. | ||
| CVE-2026-56063 | Hig | 0.00 | 8.3 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions. | ||
| CVE-2026-56061 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions. | ||
| CVE-2026-56038 | Hig | 0.00 | 8.8 | 0.00 | Jun 26, 2026 | Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions. | ||
| CVE-2026-56025 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions. |
- risk 0.00cvss 7.7epss 0.00
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP…
- risk 0.00cvss 8.2epss 0.00
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request…
- risk 0.00cvss 8.6epss 0.00
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users'…
- risk 0.00cvss 7.5epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.
- risk 0.00cvss 6.5epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and…
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
- risk 0.00cvss 6.5epss 0.00
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
- risk 0.00cvss 8.1epss 0.00
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
- risk 0.00cvss 5.8epss 0.00
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
- risk 0.00cvss 8.3epss 0.00
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
- risk 0.00cvss 8.8epss 0.00
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.