VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 74 of 464
  • CVE-2019-1003006HigFeb 6, 2019
    risk 0.50cvss 8.8epss 0.02

    A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code…

  • CVE-2013-3703HigJun 8, 2018
    risk 0.50cvss 8.8epss 0.01

    The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data.

  • CVE-2026-28571HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.

  • CVE-2026-28567HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.

  • CVE-2026-74904HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockExist, and getBlockBreadcrumb). These handlers are gated only by basic authentication (model.CheckAuth) and lack publish-access…

  • CVE-2026-16471HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.

  • CVE-2026-16467HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9.

  • CVE-2026-17087HigAug 16, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

  • CVE-2026-19728HigAug 16, 2026
    risk 0.49cvss 7.5epss 0.00

    The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product…

  • CVE-2026-72669HigAug 13, 2026
    risk 0.49cvss 7.6epss 0.00

    The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover…

  • CVE-2026-58438HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

  • CVE-2026-66469HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.

  • CVE-2026-66466HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.

  • CVE-2026-66461HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.

  • CVE-2026-66441HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.

  • CVE-2026-66431HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.

  • CVE-2026-61984HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.

  • CVE-2026-27345HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.

  • CVE-2026-73326HigAug 12, 2026
    risk 0.49cvss 7.6epss 0.00

    CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate…

  • CVE-2026-18789HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as…