CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,972 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 146 of 180
- CVE-2026-1906MEDIUMCVSS 4.3EG 4.32026-02-18
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.0 via the `wpo_ips_edi_save_order_customer_peppol_identifiers` AJAX action du…
- CVE-2026-1916HIGHCVSS 7.5EG 7.52026-02-25
The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks and an insecure authentication mechanism on the `wpgsi_callBackFuncAccept` and `wpgsi_call…
- CVE-2026-1925MEDIUMCVSS 4.3EG 4.32026-02-18
The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.…
- CVE-2026-1926MEDIUMCVSS 5.3EG 5.32026-03-18
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. …
- CVE-2026-1927MEDIUMCVSS 5.4EG 5.42026-02-05
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the greenshift_app_pass_validation() function in all versions up to, and including,…
- CVE-2026-1930MEDIUMCVSS 4.3EG 4.32026-04-22
The Emailchef plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the page_options_ajax_disconnect() function in all versions up to, and including, 3.5.1. This makes it possible for …
- CVE-2026-1932MEDIUMCVSS 5.3EG 5.32026-02-14
The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update-appointment REST API endpoint in all versions up to, and including, 1…
- CVE-2026-1934MEDIUMCVSS 4.3EG 4.32026-05-12
The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function u…
- CVE-2026-1935MEDIUMCVSS 4.3EG 4.32026-03-21
The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.0. This is due to a missing capability check on the `linkedin_company_post_reset_handler()` function hooke…
- CVE-2026-1937CRITICALCVSS 7.2EG 9.82026-02-18
The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all v…
- CVE-2026-1938MEDIUMCVSS 5.3EG 5.32026-02-18
The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due to a missing authorization check on the `/yaymail-license/v1/license/delete` REST endpoint in versions up to, and incl…
- CVE-2026-1942MEDIUMCVSS 6.5EG 6.52026-02-18
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the b2s_curation_draft AJAX action in all versions up to, and including, 8.7.4…
- CVE-2026-1944MEDIUMCVSS 5.3EG 5.32026-02-14
The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cbk_save() function in all versions up to, and including, 1.2. This makes it possible for un…
- CVE-2026-1946MEDIUMCVSS 4.3EG 4.32026-07-10
The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function in all versions up to, and including, 1.0.1. Thi…
- CVE-2026-1948MEDIUMCVSS 4.3EG 4.32026-03-16
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all versions up to, and including, 9.1.…
- CVE-2026-1981MEDIUMCVSS 4.3EG 4.32026-03-07
The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the winston_disconnect() function in all versions up to, and inc…
- CVE-2026-2001HIGHCVSS 8.8EG 8.82026-02-16
The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activate_plugin' function in all versions up to, and including, 2.1.3. This makes it possible f…
- CVE-2026-20155HIGHCVSS 8.0EG 8.02026-04-01
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to ac…
- CVE-2026-20189MEDIUMCVSS 4.3EG 4.32026-05-06
A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authoriza…
- CVE-2026-20193MEDIUMCVSS 4.3EG 4.32026-05-06
A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This …
- CVE-2026-2022MEDIUMCVSS 4.3EG 4.32026-02-14
The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and including, 2.6.99. This makes it possible …
- CVE-2026-2031CRITICALCVSS 10.0EG 10.02026-05-15
An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute a…
- CVE-2026-2038CRITICALCVSS 9.8EG 9.82026-02-20
GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this…
- CVE-2026-2039CRITICALCVSS 9.8EG 9.82026-02-20
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit thi…
- CVE-2026-20626HIGHCVSS 7.8EG 7.82026-02-11
This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges.
- CVE-2026-2065MEDIUMCVSS 8.8EG 6.32026-02-06
A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Bluetooth Low Energy Interface. Performing a manipulation results in missing authentication. …
- CVE-2026-20696MEDIUMCVSS 5.5EG 5.52026-05-11
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
- CVE-2026-20888MEDIUMCVSS 4.3EG 4.32026-01-22
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
- CVE-2026-2127MEDIUMCVSS 5.4EG 5.42026-02-18
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all versions up to, and including, 1.70.4. This is due to a missing capability check on the `siteorigin_widget_preview_widget…
- CVE-2026-21429MEDIUMCVSS 4.3EG 4.32026-01-02
Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable to edit or delete their articles after publishing them. As of time of publication, no known patched versions are availa…
- CVE-2026-21668HIGHCVSS 6.5EG 8.82026-03-12
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
- CVE-2026-21716LOWCVSS 3.3EG 3.32026-03-30
An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patc…
- CVE-2026-21743HIGHCVSS 7.2EG 7.22026-02-10
A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modi…
- CVE-2026-21836MEDIUMCVSS 6.5EG 6.52026-05-20
The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query. This could enab…
- CVE-2026-21865MEDIUMCVSS 6.5EG 6.52026-01-28
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versi…
- CVE-2026-2208MEDIUMCVSS 6.5EG 4.32026-02-08
A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be ini…
- CVE-2026-22172CRITICALCVSS 9.9EG 9.92026-03-20
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. At…
- CVE-2026-22182HIGHCVSS 7.5EG 7.52026-03-13
wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdisc…
- CVE-2026-2233MEDIUMCVSS 5.3EG 5.32026-03-16
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function …
- CVE-2026-22343HIGHCVSS 8.6EG 8.62026-06-17
Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.
- CVE-2026-22348MEDIUMCVSS 5.3EG 5.32026-01-22
Missing Authorization vulnerability in Tasos Fel Civic Cookie Control civic-cookie-control-8 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Civic Cookie Control: from n/a through <= 1.53.
- CVE-2026-22350MEDIUMCVSS 6.5EG 6.52026-02-20
Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for Elemento…
- CVE-2026-22351HIGHCVSS 7.5EG 7.52026-02-20
Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP FullCalendar: from n/a through <= 1.6.
- CVE-2026-2238MEDIUMCVSS 5.3EG 5.32026-06-25
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue …
- CVE-2026-22445MEDIUMCVSS 5.3EG 5.32026-01-22
Missing Authorization vulnerability in Proptech Plugin Apimo Connector apimo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apimo Connector: from n/a through <= 2.6.5.2.
- CVE-2026-22447MEDIUMCVSS 5.3EG 5.32026-01-22
Missing Authorization vulnerability in Select-Themes Prowess prowess allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Prowess: from n/a through <= 1.8.1.
- CVE-2026-22450MEDIUMCVSS 4.3EG 4.32026-01-22
Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3.
- CVE-2026-22458MEDIUMCVSS 4.3EG 4.32026-01-22
Missing Authorization vulnerability in Mikado-Themes Wanderland wanderland allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wanderland: from n/a through <= 1.5.
- CVE-2026-22459MEDIUMCVSS 6.5EG 6.52026-03-05
Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress CTA: from n/a through <= 2.1.2.
- CVE-2026-22461MEDIUMCVSS 5.3EG 5.32026-01-22
Missing Authorization vulnerability in WebAppick CTX Feed webappick-product-feed-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CTX Feed: from n/a through <= 6.6.18.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →