CWE-862
CVEs classified under CWE-862, newest first.
1331 CVEsRSS
CVE-2026-69724High· 8.8Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69641Critical· 9.1Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69553High· 7.1Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.
Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.
CVE-2026-69465High· 8.8Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69453Medium· 5.5Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
CVE-2026-69403Medium· 5.5Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.
Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.
CVE-2026-69380High· 8.1Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-69377High· 7.8Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
CVE-2026-47625High· 7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
CVE-2026-86840Critical· 9.1PoCThe `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying …
CVE-2026-86737Medium· 4.3snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint
snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including …
CVE-2026-86731Medium· 6.5Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action)
Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireA…
CVE-2026-86665High· 7.3PoCA vulnerability was identified in aircheng-org iWebShop-5 up to 5.15
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is…
CVE-2026-18851High· 8.8Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
CVE-2026-12647Critical· 9.9A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12646Critical· 9.9A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12645Critical· 9.9A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-77106High· 8.8Cvlaunchd contained a missing authorization issue affecting command execution authorization
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, …
CVE-2026-9331High· 7.1The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all vers…
The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all vers…
CVE-2026-85400High· 7.5Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands
Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is nor…
CVE-2026-77132Medium· 5.3It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks
It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content ele…
CVE-2026-3174High· 7.5The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it …
CVE-2026-2520Medium· 5.4The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 2…
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 2…
CVE-2026-81790High· 7.5Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommer…
Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommer…
CVE-2026-81781High· 7.1Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.
Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.
CVE-2026-76963Medium· 4.3Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information
Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could res…
CVE-2026-76962Medium· 4.3SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality
SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not…
CVE-2026-86416Medium· 5.4ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks
ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authe…
CVE-2026-86332Medium· 6.5A flaw was found in odh-dashboard in Red Hat OpenShift AI
A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data,…
CVE-2026-86274Medium· 5.3PoCA security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1
A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoContr…