VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 98 of 464
  • CVE-2023-33983HigMay 24, 2023
    risk 0.48cvss 7.4epss 0.01

    The Introduction Client in Briar through 1.5.3 does not implement out-of-band verification for the public keys of introducees. An introducer can launch man-in-the-middle attacks against later private communication between two introduced parties.

  • CVE-2023-2757HigMay 18, 2023
    risk 0.48cvss 7.4epss 0.00

    The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and…

  • CVE-2022-4940HigApr 5, 2023
    risk 0.48cvss 7.3epss 0.01

    The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide…

  • CVE-2023-1299HigMar 14, 2023
    risk 0.48cvss 7.4epss 0.01

    HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.

  • CVE-2022-21953HigFeb 7, 2023
    risk 0.48cvss 7.4epss 0.00

    A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions…

  • CVE-2020-13276HigJun 19, 2020
    risk 0.48cvss 7.4epss 0.01

    User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1

  • CVE-2020-7278HigApr 15, 2020
    risk 0.48cvss 7.4epss 0.01

    Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic…

  • CVE-2019-13673HigNov 25, 2019
    risk 0.48cvss 7.4epss 0.01

    Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2018-16081HigJan 9, 2019
    risk 0.48cvss 7.4epss 0.01

    Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system without file access permission via a crafted Chrome…

  • CVE-2018-2503HigDec 11, 2018
    risk 0.48cvss 7.4epss 0.01

    By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been fixed in SAP NetWeaver AS Java (ServerCore versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50).

  • CVE-2026-28188HigAug 13, 2026
    risk 0.47cvss 7.3epss 0.00

    Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.

  • CVE-2026-44765HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the…

  • CVE-2026-44764HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to…

  • CVE-2026-65541HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.

  • CVE-2026-19010HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the component Message API Endpoint. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit…

  • CVE-2026-6079HigAug 5, 2026
    risk 0.47cvss 7.3epss 0.00

    The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated…

  • CVE-2026-70473HigAug 4, 2026
    risk 0.47cvss epss 0.00

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response…

  • CVE-2026-61267HigJul 21, 2026
    risk 0.47cvss 7.3epss 0.00

    Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-54010HigJun 23, 2026
    risk 0.47cvss 8.3epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own chat message without checking whether they own or can read those files. If the…

  • CVE-2026-44914HigJun 22, 2026
    risk 0.47cvss 7.2epss 0.00

    Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework…