← Back
CWE-862

8,704 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,704)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Themehunk
1Wp Popup Builder
Jun 17, 2026
Sep 26, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup
1Dplugins
1Scripts Organizer
Jun 17, 2026
Sep 26, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any...Show more
The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a fileShow less
1Mailoptin
1Mailoptin
Jun 17, 2026
Sep 23, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.
1Rocketchat
1Rocket.chat
Jun 17, 2026
Sep 23, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permiss...Show more
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.Show less
1Rocketchat
1Rocket.chat
Jun 17, 2026
Sep 23, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in the getRoomRoles Meteor method leak channel members with special roles to unauthorized clients.
1Rocketchat
1Rocket.chat
Jun 17, 2026
Sep 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permi...Show more
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.Show less
1Hashicorp
1Consul
Jun 17, 2026
Sep 23, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1...Show more
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."Show less
1Teclib Edition
1System Center Configuration Manager
Jun 17, 2026
Sep 22, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in versio...Show more
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.Show less
1Liferay
2Dxp
Liferay Portal
Jul 9, 2026
Sep 22, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers...Show more
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.Show less
1Liferay
2Dxp
Liferay Portal
Jul 9, 2026
Sep 22, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowi...Show more
The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.Show less
1Jenkins
1Cons3rt
Jun 17, 2026
Sep 21, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through...Show more
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Cons3rt
Jun 17, 2026
Sep 21, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
1Jenkins
1Apprenda
Jun 17, 2026
Sep 21, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Jenkins
1Scm Httpclient
Jun 17, 2026
Sep 21, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained...Show more
A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Worksoft Execution Manager
Jun 17, 2026
Sep 21, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials ID...Show more
A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Extreme Feedback
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of exis...Show more
A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps.Show less
1Jenkins
1Dotci
Jun 17, 2026
Sep 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.
1Jenkins
1Rundeck
Jun 17, 2026
Sep 21, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permission to trigger jobs that are configured to be triggerable via Rundeck.
1Jenkins
1Rundeck
Jun 17, 2026
Sep 21, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, allowing attackers with Item/Read permission to obtain information about build artifacts of a given j...Show more
Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, allowing attackers with Item/Read permission to obtain information about build artifacts of a given job, if the optional Run/Artifacts permission is enabled.Show less
1Jenkins
1Build Publisher
Jun 17, 2026
Sep 21, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is conf...Show more
Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers.Show less