CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,975 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 155 of 180
- CVE-2026-28380MEDIUMCVSS 6.5EG 6.52026-05-13
Any Editor could delete any snapshot, even if they have no access to read or write them.
- CVE-2026-28408CRITICALCVSS 9.8EG 9.82026-02-27
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its own authentication and permission checks.…
- CVE-2026-28424MEDIUMCVSS 6.5EG 6.52026-02-27
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have…
- CVE-2026-28433MEDIUMCVSS 4.3EG 4.32026-03-10
Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but prior to 2026.3.1, contain a vulnerability that allows importing other users' data due to lack of ownership validation.…
- CVE-2026-28515HIGHCVSS 8.8EG 8.82026-02-27
openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing applicati…
- CVE-2026-28554MEDIUMCVSS 4.3EG 4.32026-02-28
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to approve or unapprove any forum post via the wpforo_approve_ajax AJAX handler. Attackers exploit the nonce-only check by submitting …
- CVE-2026-28555MEDIUMCVSS 4.3EG 4.32026-02-28
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to close or reopen any forum topic via the wpforo_close_ajax handler. Attackers submit a valid nonce with an arbitrary topic ID to byp…
- CVE-2026-28556MEDIUMCVSS 5.4EG 5.42026-02-28
wpForo Forum 2.4.14 contains a missing authorization vulnerability that allows authenticated subscribers to move, merge, or split any forum topic via the topic_move, topic_merge, and topic_split form action handlers. Attackers with a valid…
- CVE-2026-28557MEDIUMCVSS 6.5EG 6.52026-02-28
wpForo Forum 2.4.14 contains a missing capability check vulnerability that allows authenticated users to trigger bulk wpForo usergroup reassignment via the wpforo_synch_roles AJAX handler. Attackers access the usergroups admin page, access…
- CVE-2026-28573MEDIUMCVSS 5.5EG 5.52026-06-18
In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2026-28587MEDIUMCVSS 5.5EG 5.52026-06-17
In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User int…
- CVE-2026-28615HIGHCVSS 7.8EG 7.82026-06-17
In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex…
- CVE-2026-28790HIGHCVSS 7.5EG 7.52026-03-05
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to terminate running actions through KillAction even when authRequireGuestsToLogin: true is enabl…
- CVE-2026-2890HIGHCVSS 7.5EG 7.52026-03-13
The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment reco…
- CVE-2026-2899MEDIUMCVSS 6.5EG 6.52026-03-05
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce verification and capa…
- CVE-2026-2900LOWCVSS 2.7EG 2.72026-05-14
GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authen…
- CVE-2026-29070HIGHCVSS 8.1EG 8.12026-03-27
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an access control check is missing when deleting a file from a knowledge base. The only check being done is that the…
- CVE-2026-29072HIGHCVSS 7.5EG 7.52026-03-19
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the …
- CVE-2026-29073HIGHCVSS 8.8EG 8.82026-03-06
SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic auth, not admin rights, any logged-in user, even readers, can run any sql query on the data…
- CVE-2026-29180HIGHCVSS 8.8EG 8.82026-03-27
Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from any team into their own team, bypassing team isolation bou…
- CVE-2026-2941HIGHCVSS 8.8EG 8.82026-03-21
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. T…
- CVE-2026-29515CRITICALCVSS 9.8EG 9.82026-03-11
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinati…
- CVE-2026-29789HIGHCVSS 8.8EG 8.82026-03-06
Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization check in workflow site-creation actions allows an authenticated attacker …
- CVE-2026-2992HIGHCVSS 8.2EG 8.22026-03-18
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, an…
- CVE-2026-30233MEDIUMCVSS 4.3EG 4.32026-03-06
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization flaw in OliveTin allows authenticated users with view: false permission to enumerate action bindings and metadata via das…
- CVE-2026-3045HIGHCVSS 7.5EG 7.52026-03-13
The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a no…
- CVE-2026-3056MEDIUMCVSS 4.3EG 4.32026-03-04
The Seraphinite Accelerator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `seraph_accel_api` AJAX action with `fn=LogClear` in all versions up to, and including, 2.28.14. T…
- CVE-2026-3072MEDIUMCVSS 4.3EG 4.32026-03-05
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes …
- CVE-2026-30797HIGHCVSS 8.1EG 8.12026-03-05
Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Mi…
- CVE-2026-30823HIGHCVSS 8.8EG 8.82026-03-07
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue h…
- CVE-2026-30842MEDIUMCVSS 4.3EG 4.32026-03-07
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenticated user to delete avatar files uploaded by other users. The avatar deletion endpoint does not verify that the reques…
- CVE-2026-30845HIGHCVSS 8.2EG 8.22026-03-06
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integration data for a board without any field filtering, exposing sensitive fields including we…
- CVE-2026-30850MEDIUMCVSS 5.9EG 5.92026-03-07
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.9 and 9.5.0-alpha.9, the file metadata endpoint (GET /files/:appId/metadata/:filename) does not enforce beforeFin…
- CVE-2026-30885MEDIUMCVSS 5.3EG 5.32026-03-10
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate u…
- CVE-2026-30889MEDIUMCVSS 4.9EG 4.92026-03-20
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderator could exploit insufficient authorization checks to access metadata of posts they should not have permission to view. …
- CVE-2026-30911HIGHCVSS 8.1EG 8.12026-03-17
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to a…
- CVE-2026-30920HIGHCVSS 8.6EG 8.62026-03-10
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: tru…
- CVE-2026-30926HIGHCVSS 7.1EG 7.12026-03-10
SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note that allows low-privilege publish accounts (RoleReader) to modify notebook content via the…
- CVE-2026-30950HIGHCVSS 7.1EG 7.12026-05-18
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attac…
- CVE-2026-30956CRITICALCVSS 9.9EG 9.92026-03-10
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged is-multi-tenant-query header…
- CVE-2026-30959MEDIUMCVSS 5.0EG 5.02026-03-10
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (u…
- CVE-2026-30968CRITICALCVSS 9.8EG 9.82026-03-10
Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, the SSE endpoint (/sse/v1/...) in Coral Server did not strongly validate that a conn…
- CVE-2026-30970CRITICALCVSS 9.1EG 9.12026-03-10
Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, Coral Server allowed the creation of agent sessions through the /api/v1/sessions end…
- CVE-2026-3098MEDIUMCVSS 6.5EG 6.52026-03-27
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level acces…
- CVE-2026-3117MEDIUMCVSS 6.5EG 6.52026-05-18
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab…
- CVE-2026-31241MEDIUMCVSS 6.5EG 6.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory records by specifying arbitrary user identifiers (e.g…
- CVE-2026-31242CRITICALCVSS 9.1EG 9.12026-05-12
The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that triggers a reset operation, …
- CVE-2026-31243MEDIUMCVSS 6.5EG 6.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that trigger…
- CVE-2026-31244MEDIUMCVSS 6.5EG 6.52026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated users to delete arbitrary memory records without verifying their…
- CVE-2026-31245MEDIUMCVSS 5.3EG 5.32026-05-12
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary memory records without verifying their identity or p…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →