CWE-862: Missing Authorization — known CVE vulnerabilities
CVEs classified under CWE-862 (Missing Authorization), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-101000 — CVSS 10.0 (critical): A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file…
CVE-2026-97360 — CVSS 10.0 (critical): HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to…
CVE-2026-65381 — CVSS 10.0 (critical): A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement…
CVE-2026-81648 — CVSS 10.0 (critical): The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing…
CVE-2026-77770 — CVSS 10.0 (critical): The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction…
CVE-2026-65667 — CVSS 10.0 (critical): Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-48168 — CVSS 10.0 (critical): PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command…
CVE-2026-66012 — CVSS 10.0 (critical): SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth…
CVE-2026-0092: In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local…
CVE-2026-33712 — CVSS 10.0 (critical): Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startC…
CVE-2026-2031: An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23…
CVE-2026-34976 — CVSS 10.0 (critical): Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization…
CVE-2025-30416 — CVSS 10.0 (critical): Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16…
CVE-2025-46348 — CVSS 10.0 (critical): YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded…
CVE-2025-22609 — CVSS 10.0 (critical): Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the…
CVE-2024-52416 — CVSS 10.0 (critical): Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects…
CVE-2024-6500 — CVSS 10.0 (critical): The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a…
CVE-2024-6071 — CVSS 10.0 (critical): PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary…
CVE-2024-33566 — CVSS 10.0 (critical): Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.
CVE-2024-2086 — CVSS 10.0 (critical): The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your…
CVE-2026-82041 — CVSS 9.9 (critical): UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped…
CVE-2026-82377 — CVSS 9.9 (critical): Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other…
CVE-2026-84719 — CVSS 9.9 (critical): A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission…
CVE-2026-79920 — CVSS 9.9 (critical): Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to…
CVE-2026-20324 — CVSS 9.9 (critical): A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow…
CVE-2026-12647 — CVSS 9.9 (critical): A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary…
CVE-2026-12646 — CVSS 9.9 (critical): A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary…
CVE-2026-12645 — CVSS 9.9 (critical): A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary…
CVE-2026-79748 — CVSS 9.9 (critical): MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with…
CVE-2026-62940 — CVSS 9.9 (critical): Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member…
CVE-2026-48751 — CVSS 9.9 (critical): Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlev…
CVE-2026-63300 — CVSS 9.9 (critical): An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker…
CVE-2026-19656 — CVSS 9.9 (critical): ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only…
CVE-2026-72864 — CVSS 9.9 (critical): Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in…
CVE-2026-62830 — CVSS 9.9 (critical): Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-47724 — CVSS 9.9 (critical): nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route…
CVE-2026-45625 — CVSS 9.9 (critical): Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes…
CVE-2026-46425 — CVSS 9.9 (critical): Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares…
CVE-2026-44442 — CVSS 9.9 (critical): ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper…
CVE-2026-39355 — CVSS 9.9 (critical): Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application…
CVE-2026-22172 — CVSS 9.9 (critical): OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token…
CVE-2026-29789 — CVSS 9.9 (critical): Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version…
CVE-2026-0488 — CVSS 9.9 (critical): An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute…
CVE-2025-68270 — CVSS 9.9 (critical): The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole…
CVE-2025-49747 — CVSS 9.9 (critical): Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
CVE-2025-22611 — CVSS 9.9 (critical): Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the…