← Back
CWE-862

10,089 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (10,089)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Blogengine
1Blogengine.net
Jun 17, 2026
Mar 6, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
1Ghost
1Ghost
Jun 17, 2026
Mar 5, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published...Show more
Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this behavior has no security impact.Show less
1Eskom
1E Belediye
Jun 17, 2026
Mar 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.100.
1Joomunited
1Wp Meta Seo
Jun 17, 2026
Feb 28, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the checkAllCategoryInSitemap function in versions up to, and including, 4.5.3. This makes it pos...Show more
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the checkAllCategoryInSitemap function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to obtain post categories. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.Show less
1Joomunited
1Wp Meta Seo
Jun 17, 2026
Feb 28, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the listPostsCategory function in versions up to, and including, 4.5.3. This makes it possible for au...Show more
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the listPostsCategory function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to get post listings by category as long as those posts are published. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.Show less
1Joomunited
1Wp Meta Seo
Jun 17, 2026
Feb 28, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the regenerateSitemaps function in versions up to, and including, 4.5.3. This makes it possible f...Show more
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the regenerateSitemaps function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to generate sitemaps. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.Show less
1Joomunited
1Wp Meta Seo
Jun 17, 2026
Feb 28, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the saveSitemapSettings function in versions up to, and including, 4.5.3. This makes it possi...Show more
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the saveSitemapSettings function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to change sitemap-related settings of the plugin. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.Show less
1Joomunited
1Wp Meta Seo
Jun 17, 2026
Feb 28, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on the wpmsGGSaveInformation function in versions up to, and including, 4.5.3. This makes it possible fo...Show more
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on the wpmsGGSaveInformation function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to update google analytics options maintained by the plugin. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Feb 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.
1Mattermost
1Mattermost
Jun 17, 2026
Feb 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Ex...Show more
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.Show less
1Intuitive Custom Post Order Project
1Intuitive Custom Post Order
Jun 17, 2026
Feb 21, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order
1Checkmk
1Checkmk
Jun 17, 2026
Feb 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags with...Show more
No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags within Rest API documentation.Show less
1Jenkins
1Synopsys Coverity
Jun 17, 2026
Feb 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Jenkins
1Synopsys Coverity
Jun 17, 2026
Feb 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtain...Show more
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Azure Credentials
Jun 17, 2026
Feb 15, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.
1Jenkins
1Azure Credentials
Jun 17, 2026
Feb 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Sap
1Fiori
Jun 17, 2026
Feb 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is norma...Show more
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents. Show less
1Sap
1S/4hana
Jun 17, 2026
Feb 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a...Show more
SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability. Show less
1Sap
1Netweaver Application Server Abap
Jun 17, 2026
Feb 14, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privile...Show more
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Show less