CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,975 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 153 of 180
- CVE-2026-2633MEDIUMCVSS 4.3EG 4.32026-02-18
The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.1. This is due to a missing capability check in the `process_image_data_ajax_callback()` funct…
- CVE-2026-26358HIGHCVSS 8.8EG 8.82026-02-19
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
- CVE-2026-26367HIGHCVSS 8.1EG 8.12026-02-15
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated low-privileged user (UG_USER) to delete arbitrary user accounts, except for the b…
- CVE-2026-26368HIGHCVSS 8.8EG 8.82026-02-15
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword JSON-RPC method that allows any authenticated low-privileged user (UG_USER) to reset the password of arbitrary accounts, includi…
- CVE-2026-2651CRITICALCVSS 9.0EG 9.02026-05-25
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/m…
- CVE-2026-2658MEDIUMCVSS 4.3EG 4.32026-02-18
A vulnerability was found in newbee-ltd newbee-mall up to a069069b07027613bf0e7f571736be86f431faee. Affected is an unknown function of the component Multiple Endpoints. Performing a manipulation results in cross-site request forgery. Remot…
- CVE-2026-26741HIGHCVSS 8.1EG 8.12026-03-10
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" state (after landing and before the automatic disarm triggere…
- CVE-2026-26742HIGHCVSS 8.1EG 8.12026-03-10
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mod…
- CVE-2026-26939MEDIUMCVSS 6.5EG 6.52026-03-19
Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functi…
- CVE-2026-26977MEDIUMCVSS 5.3EG 5.32026-02-20
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this…
- CVE-2026-26979LOWCVSS 2.7EG 2.72026-02-26
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able to close, archive and pin topics in private categories they don't have access to. Versions 2025.12.2, 2026.1.1, and 20…
- CVE-2026-27021MEDIUMCVSS 5.3EG 5.32026-02-26
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoint in the poll plugin lacked post visibility checks which allowed unauthorized access to voters details of polls in any …
- CVE-2026-27042MEDIUMCVSS 5.3EG 5.32026-02-19
Missing Authorization vulnerability in WPDeveloper NotificationX notificationx allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NotificationX: from n/a through <= 3.2.1.
- CVE-2026-27046MEDIUMCVSS 6.5EG 6.52026-03-25
Missing Authorization vulnerability in Kaira StoreCustomizer woocustomizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects StoreCustomizer: from n/a through <= 2.6.3.
- CVE-2026-27055MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in PenciDesign Penci AI SmartContent Creator penci-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Penci AI SmartContent Creator: from n/a through <= 2.0.
- CVE-2026-27056MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in StellarWP iThemes Sync ithemes-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through <= 3.2.8.
- CVE-2026-27071CRITICALCVSS 9.1EG 9.12026-03-25
Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through <= 3.0.7.
- CVE-2026-27091MEDIUMCVSS 6.3EG 6.32026-03-19
Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UiPress lite: from n/a through <= 3.5.09.
- CVE-2026-27092MEDIUMCVSS 6.5EG 6.52026-02-19
Missing Authorization vulnerability in Greg Winiarski WPAdverts wpadverts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPAdverts: from n/a through <= 2.3.0.
- CVE-2026-27111MEDIUMCVSS 5.0EG 5.02026-02-20
Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model includes a promote verb -- a non-standard Kubernetes "dolphin verb" -- that gates the ability to advance Freight through a …
- CVE-2026-27150LOWCVSS 3.8EG 3.82026-02-26
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_before_create` authorization in Data Explorer's `QueryGroupBookmarkable` allows any logged-in user to create bookmarks …
- CVE-2026-27151LOWCVSS 2.7EG 2.72026-02-26
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` action only checked `can_move_posts?` on the source topic but never validated write permissions on the destination topic…
- CVE-2026-27181HIGHCVSS 7.5EG 7.52026-02-18
MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() method reads gr('mode') from $_REQUEST and assigns it to $this->mode at the start of execut…
- CVE-2026-2720MEDIUMCVSS 6.5EG 6.52026-03-21
The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-fetch-employees` AJAX action in all versions up to, and including, 1.0.2. This makes it po…
- CVE-2026-2732MEDIUMCVSS 5.4EG 5.42026-03-04
The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This m…
- CVE-2026-27327MEDIUMCVSS 4.3EG 4.32026-02-19
Missing Authorization vulnerability in YayCommerce YayMail yaymail allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayMail: from n/a through <= 4.3.2.
- CVE-2026-27328MEDIUMCVSS 5.3EG 5.32026-02-19
Missing Authorization vulnerability in DevsBlink EduBlink edublink allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EduBlink: from n/a through <= 2.0.7.
- CVE-2026-27331MEDIUMCVSS 6.3EG 6.32026-05-26
Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5.
- CVE-2026-27344MEDIUMCVSS 5.9EG 5.92026-03-05
Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects inseri core: from n/a through <= 1.0.5.
- CVE-2026-27346MEDIUMCVSS 4.9EG 4.92026-05-25
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a before 5.2.10.
- CVE-2026-27351MEDIUMCVSS 5.4EG 5.42026-06-02
Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2.
- CVE-2026-27355MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
- CVE-2026-27357MEDIUMCVSS 5.3EG 5.32026-05-25
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Search Analytics: from n/a before 1.5.0.
- CVE-2026-27361HIGHCVSS 7.5EG 7.52026-03-05
Missing Authorization vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Posts Carousel Pro: fro…
- CVE-2026-27362MEDIUMCVSS 6.5EG 6.52026-03-05
Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bakery Autoresponder Addon: from n/a thr…
- CVE-2026-27366HIGHCVSS 7.5EG 7.52026-06-25
Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
- CVE-2026-27368MEDIUMCVSS 5.3EG 5.92026-02-19
Missing Authorization vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coming Soon Page, Un…
- CVE-2026-27374HIGHCVSS 7.5EG 7.52026-03-05
Missing Authorization vulnerability in vanquish WooCommerce Order Details woocommerce-order-details allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Order Details: from n/a through <= 3…
- CVE-2026-27377MEDIUMCVSS 6.7EG 6.72026-07-23
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
- CVE-2026-27386HIGHCVSS 7.5EG 7.52026-03-05
Missing Authorization vulnerability in designthemes DesignThemes Directory Addon designthemes-directory-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Directory Addon: from n/a…
- CVE-2026-27387MEDIUMCVSS 5.4EG 5.42026-02-19
Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through <= 3.6.26.
- CVE-2026-27388HIGHCVSS 7.5EG 7.52026-03-05
Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Booking Manager: from n/a…
- CVE-2026-27391MEDIUMCVSS 5.4EG 5.42026-07-23
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
- CVE-2026-27392MEDIUMCVSS 4.3EG 4.32026-07-23
Contributor Broken Access Control in uListing <= 2.2.0 versions.
- CVE-2026-27393MEDIUMCVSS 5.3EG 5.32026-05-21
Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 WOW Styler: from n/a through 1.7.6.
- CVE-2026-27396HIGHCVSS 7.3EG 7.32026-03-05
Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6.
- CVE-2026-27398MEDIUMCVSS 5.3EG 5.32026-05-25
Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16.
- CVE-2026-27399MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
- CVE-2026-27405MEDIUMCVSS 6.5EG 6.52026-05-20
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
- CVE-2026-27409MEDIUMCVSS 5.3EG 5.32026-07-01
Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly... Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →