CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,975 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 154 of 180
- CVE-2026-27416MEDIUMCVSS 5.3EG 5.32026-05-07
Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF Poster: from n/a through 2.4.1.
- CVE-2026-27418MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
- CVE-2026-27422MEDIUMCVSS 5.3EG 5.32026-07-23
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
- CVE-2026-27423MEDIUMCVSS 4.3EG 4.32026-07-23
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
- CVE-2026-27424MEDIUMCVSS 4.3EG 4.32026-05-20
Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11.
- CVE-2026-27433MEDIUMCVSS 6.5EG 6.52026-07-02
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
- CVE-2026-27435MEDIUMCVSS 5.3EG 5.32026-07-01
Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.
- CVE-2026-27454MEDIUMCVSS 5.3EG 5.32026-03-19
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The display_post method called post.revert_…
- CVE-2026-27457MEDIUMCVSS 4.3EG 4.32026-02-26
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permiss…
- CVE-2026-27468HIGHCVSS 8.2EG 8.22026-02-24
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe …
- CVE-2026-27471CRITICALCVSS 9.1EG 9.12026-02-21
ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been f…
- CVE-2026-27484MEDIUMCVSS 4.3EG 4.32026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, instead of trusted runtime sender context.…
- CVE-2026-27491MEDIUMCVSS 4.3EG 4.32026-03-19
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a sta…
- CVE-2026-27604CRITICALCVSS 10.0EG 10.02026-06-23
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` end…
- CVE-2026-27608HIGHCVSS 8.1EG 8.12026-02-25
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to…
- CVE-2026-27638HIGHCVSS 7.1EG 7.12026-02-26
Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being operated on. Any authenti…
- CVE-2026-27672MEDIUMCVSS 4.3EG 4.32026-04-14
The Material Master application does not enforce authorization checks for authenticated users when executing reports, resulting in the disclosure of sensitive information. This vulnerability has a low impact on confidentiality and does not…
- CVE-2026-27673MEDIUMCVSS 4.9EG 4.92026-04-14
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Conf…
- CVE-2026-27676MEDIUMCVSS 4.3EG 4.32026-04-14
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability resul…
- CVE-2026-27677MEDIUMCVSS 6.5EG 6.52026-04-14
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could update and delete child entities via OData services without proper authorization. This vulnerability has a high impact on …
- CVE-2026-27678MEDIUMCVSS 6.5EG 6.52026-04-14
Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has …
- CVE-2026-27679MEDIUMCVSS 6.5EG 6.52026-04-14
Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has…
- CVE-2026-27686MEDIUMCVSS 5.9EG 5.92026-03-10
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration…
- CVE-2026-27687MEDIUMCVSS 5.8EG 5.82026-03-10
Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does…
- CVE-2026-27688MEDIUMCVSS 5.0EG 5.02026-03-10
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary pr…
- CVE-2026-27708HIGHCVSS 7.1EG 7.12026-06-24
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authent…
- CVE-2026-27769LOWCVSS 2.7EG 2.72026-04-15
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed…
- CVE-2026-27771HIGHCVSS 8.2EG 8.42026-07-03
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
- CVE-2026-27783MEDIUMCVSS 4.3EG 4.32026-06-16
Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
- CVE-2026-27792MEDIUMCVSS 5.4EG 5.42026-02-27
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified in the application starting in version 2.7.0 and prior to version 3.1.0. It allows authenti…
- CVE-2026-27796HIGHCVSS 7.5EG 7.52026-03-07
Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata …
- CVE-2026-27833HIGHCVSS 7.5EG 7.52026-04-03
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing hi…
- CVE-2026-27836HIGHCVSS 7.5EG 7.52026-02-27
phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active user accounts without any authentication, CSRF protection, captcha, or configuration checks…
- CVE-2026-27946MEDIUMCVSS 6.5EG 6.52026-02-26
ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual ver…
- CVE-2026-27954MEDIUMCVSS 6.5EG 6.52026-02-26
Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without cal…
- CVE-2026-28038MEDIUMCVSS 6.5EG 6.52026-03-05
Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Pa…
- CVE-2026-28070MEDIUMCVSS 5.3EG 5.32026-03-19
Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP eMember: from n/a through v10.2.2.
- CVE-2026-28071MEDIUMCVSS 6.3EG 6.32026-03-05
Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pixfort Core: from n/a through <= 3.2.22.
- CVE-2026-28076HIGHCVSS 7.5EG 7.52026-03-05
Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Guff: from n/a through <= 1.0.1.
- CVE-2026-28080MEDIUMCVSS 4.3EG 4.32026-03-06
Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO PRO: from n/a through 3.0.95.
- CVE-2026-28104MEDIUMCVSS 6.5EG 6.52026-03-05
Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Site Suggest: from n/a through <= 1.3.9.
- CVE-2026-2819MEDIUMCVSS 6.3EG 6.32026-02-20
A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to mi…
- CVE-2026-28193HIGHCVSS 5.3EG 8.82026-02-25
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
- CVE-2026-28195MEDIUMCVSS 4.3EG 4.32026-02-25
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
- CVE-2026-28217MEDIUMCVSS 6.5EG 6.52026-02-26
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection ID and returns the full collection data — including title, type, and the serialized `da…
- CVE-2026-28254HIGHCVSS 7.5EG 7.52026-03-12
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
- CVE-2026-2826MEDIUMCVSS 4.3EG 4.32026-04-04
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the `…
- CVE-2026-28276HIGHCVSS 7.5EG 7.52026-02-26
Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded documents are served from a publicly accessible /uploads/ directory without any authentic…
- CVE-2026-28309CRITICALCVSS 9.1EG 9.12026-07-21
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
- CVE-2026-28310CRITICALCVSS 9.1EG 9.12026-07-21
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →