← Back
CWE-862

9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (9,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elastic
1Kibana
Sep 2, 2026
Aug 13, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kiban...Show more
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.Show less
1Elastic
1Kibana
Sep 2, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who h...Show more
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate automated endpoint response actions with a detection rule, even though the dedicated Endpoint response action privileges that govern those capabilities (host isolation, process operations, and execute operations) have not been granted to that user. When such a rule generates alerts, the associated response actions are carried out against the matching hosts.Show less
1Elastic
1Kibana
Sep 2, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend end...Show more
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution and endpoint privileges that its user-facing equivalents require, and it retrieved data with elevated internal permissions rather than the permissions of the requesting user. As a result, an authenticated low-privileged Kibana user with no Security Solution privileges, endpoint privileges and no Elasticsearch privileges on the underlying data, could read endpoint response action records and the corresponding response content returned by managed hosts.Show less
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including...Show more
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a channel:-prefixed chat_id and a target message_id. The channel: path routes pipeline output through _make_channel_emitter, which writes to the Messages table using the caller-supplied message_id without binding it to the channel. This issue is fixed in version 0.10.0.Show less
-
-
Sep 9, 2026
Aug 13, 2026
N/A· v4
9.4 CRITICAL· v3
N/A· v2
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and ann...Show more
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. This issue is fixed in versions 3.2.7, 4.1.10, and 5.0.0-beta.6.Show less
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Private Repository Metadata Remains Accessible After Access Revocation
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Cross-repository issue/comment attachment re-linking can expose private attachment content
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.