CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 74 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1003006 | Hig | 0.50 | 8.8 | 0.02 | Feb 6, 2019 | A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code… | ||
| CVE-2013-3703 | Hig | 0.50 | 8.8 | 0.01 | Jun 8, 2018 | The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data. | ||
| CVE-2026-28571 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. | ||
| CVE-2026-28567 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | ||
| CVE-2026-74904 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockExist, and getBlockBreadcrumb). These handlers are gated only by basic authentication (model.CheckAuth) and lack publish-access… | ||
| CVE-2026-16471 | Hig | 0.49 | 7.5 | 0.00 | Aug 17, 2026 | Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8. | ||
| CVE-2026-16467 | Hig | 0.49 | 7.5 | 0.00 | Aug 17, 2026 | Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9. | ||
| CVE-2026-17087 | Hig | 0.49 | 7.5 | 0.00 | Aug 16, 2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This… | ||
| CVE-2026-19728 | Hig | 0.49 | 7.5 | 0.00 | Aug 16, 2026 | The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product… | ||
| CVE-2026-72669 | Hig | 0.49 | 7.6 | 0.00 | Aug 13, 2026 | The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover… | ||
| CVE-2026-58438 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | ||
| CVE-2026-66469 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | ||
| CVE-2026-66466 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. | ||
| CVE-2026-66461 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | ||
| CVE-2026-66441 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. | ||
| CVE-2026-66431 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | ||
| CVE-2026-61984 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. | ||
| CVE-2026-27345 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. | ||
| CVE-2026-73326 | Hig | 0.49 | 7.6 | 0.00 | Aug 12, 2026 | CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate… | ||
| CVE-2026-18789 | Hig | 0.49 | 7.5 | 0.00 | Aug 12, 2026 | The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as… |
- risk 0.50cvss 8.8epss 0.02
A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code…
- risk 0.50cvss 8.8epss 0.01
The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
- risk 0.49cvss 7.5epss 0.00
SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockExist, and getBlockBreadcrumb). These handlers are gated only by basic authentication (model.CheckAuth) and lack publish-access…
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9.
- risk 0.49cvss 7.5epss 0.00
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…
- risk 0.49cvss 7.5epss 0.00
The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product…
- risk 0.49cvss 7.6epss 0.00
The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover…
- risk 0.49cvss 7.5epss 0.00
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
- risk 0.49cvss 7.6epss 0.00
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate…
- risk 0.49cvss 7.5epss 0.00
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as…