← Back
CWE-862

8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,681)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of...Show more
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.Show less
1Bitwarden
1Server
Jul 14, 2026
Jun 25, 2026
5.3 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvo...Show more
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization checks. Attackers can exploit the missing ManageOrganizationBillingRequirement on the preview invoice endpoints to retrieve Stripe-computed tax totals, subscription status, and billing details derived from any target organization's real customer and subscription data.Show less
1Bitwarden
1Server
Jul 14, 2026
Jun 25, 2026
7.1 HIGH· v4
7.1 HIGH· v3
N/A· v2
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role...Show more
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin organization-user IDs in a bulk DELETE request to bypass the guard enforced on the single-user removal path, effectively removing one or more Admin accounts from an organization.Show less
-
-
Jun 26, 2026
Jun 25, 2026
N/A· v4
4.2 MEDIUM· v3
N/A· v2
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unau...Show more
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.Show less
-
-
Jul 14, 2026
Jun 25, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET e...Show more
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download entire shared directory trees.Show less
-
-
Jul 14, 2026
Jun 25, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can...Show more
Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify, delete, or execute other users' robots by bypassing ownership checks in API endpoints.Show less
1Librechat
1Librechat
Jun 29, 2026
Jun 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messag...Show more
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messages. The validateMessageReq middleware only validates that the conversationId belongs to the requesting user, but the handler calls deleteMessages({ messageId }) using only the messageId as the MongoDB filter — without adding a user constraint. An attacker provides their own valid conversationId (to pass validation) and the victim's messageId (to target deletion), resulting in permanent, irrecoverable message deletion. This vulnerability is fixed in 0.8.4-rc1.Show less
1Librechat
1Librechat
Jun 26, 2026
Jun 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool_resources (e.g., con...Show more
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool_resources (e.g., context, execute_code) without verifying ownership or EDIT permission on the target agent. A permission check was added to the POST /api/files route in a previous patch, but the image upload route was never updated with the same check. An attacker can simply use the image endpoint instead of the file endpoint to bypass the authorization entirely. This vulnerability is fixed in 0.8.4-rc1.Show less
1Joomlaworks
1K2
Jun 28, 2026
Jun 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/`
-
-
Jun 25, 2026
Jun 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
-
-
Jun 25, 2026
Jun 25, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
-
-
Jun 25, 2026
Jun 25, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
-
-
Jun 29, 2026
Jun 25, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
-
-
Jun 25, 2026
Jun 25, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.
-
-
Jun 29, 2026
Jun 25, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
-
-
Jun 25, 2026
Jun 25, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
-
-
Jun 29, 2026
Jun 25, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
1Gitlab
1Gitlab
Jun 26, 2026
Jun 25, 2026
N/A· v4
3.1 LOW· v3
N/A· v2
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited...Show more
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficient authorization checks.Show less