CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,975 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 152 of 180
- CVE-2026-25416MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <…
- CVE-2026-25419MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UpsellWP: from n/a through <= 2.2.5.
- CVE-2026-25420MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18.
- CVE-2026-25423LOWCVSS 3.8EG 3.82026-02-19
Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.19.1.
- CVE-2026-25424MEDIUMCVSS 4.3EG 4.32026-07-23
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
- CVE-2026-25425HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.
- CVE-2026-25426MEDIUMCVSS 5.3EG 5.32026-05-26
Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through…
- CVE-2026-25427MEDIUMCVSS 5.4EG 5.42026-07-23
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
- CVE-2026-25430MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-mailchimp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integra…
- CVE-2026-25431MEDIUMCVSS 5.3EG 5.32026-05-12
Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.
- CVE-2026-25436MEDIUMCVSS 5.3EG 5.32026-05-07
Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.
- CVE-2026-25437MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in سید محمدامین هاشمی GZSEO gzseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GZSEO: from n/a through <= 2.0.14.
- CVE-2026-25440MEDIUMCVSS 5.3EG 5.32026-06-15
Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
- CVE-2026-25441MEDIUMCVSS 5.3EG 5.32026-02-19
Missing Authorization vulnerability in varunvairavanlc LeadConnector leadconnector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LeadConnector: from n/a through <= 3.0.21.
- CVE-2026-25443HIGHCVSS 7.5EG 7.52026-03-19
Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …
- CVE-2026-25444MEDIUMCVSS 4.3EG 4.32026-05-26
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
- CVE-2026-25454MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in MVPThemes The League the-league allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The League: from n/a through <= 4.4.1.
- CVE-2026-25455MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Slider for WooCommerce: from n…
- CVE-2026-25456HIGHCVSS 7.3EG 7.52026-03-25
Missing Authorization vulnerability in Aarsiv Groups Automated FedEx live/manual rates with shipping labels a2z-fedex-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automated FedEx live/…
- CVE-2026-25459MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in uixthemes Sober sober allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sober: from n/a through <= 3.5.12.
- CVE-2026-25460MEDIUMCVSS 6.3EG 6.32026-03-25
Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ave Core: from n/a through <= 2.9.1.
- CVE-2026-25462MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in avalex avalex avalex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects avalex: from n/a through <= 3.1.3.
- CVE-2026-25466MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
- CVE-2026-25469MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ViaBill – WooCommerce: from n/a through…
- CVE-2026-25473MEDIUMCVSS 5.4EG 5.42026-02-19
Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31.
- CVE-2026-25517LOWCVSS 2.7EG 2.72026-02-04
Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7.3, due to a missing permission check on the preview endpoints, a user with access to the Wagtail admin and knowledge o…
- CVE-2026-25531MEDIUMCVSS 4.3EG 4.32026-02-13
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projec…
- CVE-2026-25538HIGHCVSS 8.8EG 8.82026-02-04
Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API interface, allowing any authenticated user (including low-privileged CI/CD Developers) to ob…
- CVE-2026-2559MEDIUMCVSS 5.3EG 5.32026-03-18
The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the fun…
- CVE-2026-25609MEDIUMCVSS 4.3EG 5.42026-02-10
Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.
- CVE-2026-25633MEDIUMCVSS 4.3EG 4.32026-02-11
Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without perm…
- CVE-2026-25714MEDIUMCVSS 4.3EG 4.32026-06-16
Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.
- CVE-2026-25742MEDIUMCVSS 5.3EG 5.32026-04-03
Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, even after spectator access (enable_spectator_access / WEB_PUBLIC_STREAMS_E…
- CVE-2026-25752CRITICALCVSS 9.1EG 9.12026-02-06
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation allows an unauthenticated…
- CVE-2026-25768MEDIUMCVSS 6.5EG 6.52026-02-12
LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in 2.6.6.
- CVE-2026-25806MEDIUMCVSS 6.5EG 6.52026-02-09
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the GET /api/students/:email PUT /api/students/:email/status, and DELETE /api/students/:email routes in backend/src/routes/student.routes.ts …
- CVE-2026-25808HIGHCVSS 7.5EG 7.52026-02-09
Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outb…
- CVE-2026-25810CRITICALCVSS 9.1EG 9.12026-02-09
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks).
- CVE-2026-25876CRITICALCVSS 9.1EG 9.12026-02-09
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks). For exampl…
- CVE-2026-25903MEDIUMCVSS 6.6EG 6.62026-02-17
Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additi…
- CVE-2026-25939CRITICALCVSS 9.1EG 9.12026-02-09
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary sched…
- CVE-2026-2601MEDIUMCVSS 4.3EG 4.32026-05-27
GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permission…
- CVE-2026-2608MEDIUMCVSS 4.3EG 4.32026-02-17
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.32. This makes it possible…
- CVE-2026-26083CRITICALCVSS 9.8EG 9.82026-05-12
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSa…
- CVE-2026-26103HIGHCVSS 7.1EG 7.12026-02-25
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned u…
- CVE-2026-26104MEDIUMCVSS 5.5EG 5.52026-02-25
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metad…
- CVE-2026-26207MEDIUMCVSS 5.4EG 5.42026-02-26
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy` plugin allows any authenticated user to interact with policies on posts they do not have permission to view. The `Poli…
- CVE-2026-26236HIGHCVSS 7.5EG 7.52026-06-09
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the…
- CVE-2026-26237HIGHCVSS 7.5EG 7.52026-06-10
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the…
- CVE-2026-26268HIGHCVSS 9.9EG 8.02026-02-13
Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, includin…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →