CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,064
Total CVEs
229
Critical
867
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
440
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 125
2 Sap 36
3 Apple 27
4 Jenkins 22
5 Gitlab 19
6 Xwiki 12
7 Themeum 12
8 Metagauss 11
9 Wpdeveloper 11
10 Q Free 11

All Missing Authorization CVEs (3,064)

CVE-2025-14350
4.3

This vulnerability allows authenticated Mattermost users to discover the existence of teams and their URL names by posting channel shortlinks and obse...

Feb 16, 2026
CVE-2026-0929
4.3

The RegistrationMagic WordPress plugin before version 6.0.7.2 lacks proper capability checks, allowing users with subscriber-level permissions or high...

Feb 16, 2026
CVE-2026-2312
4.3

The Media Library Folders WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Author-level...

Feb 14, 2026
CVE-2026-25531
4.3

This vulnerability allows authenticated Kanboard users to duplicate tasks into projects they shouldn't have access to, bypassing permission controls. ...

Feb 13, 2026
CVE-2026-24327
4.3

This vulnerability in SAP Strategic Enterprise Management allows authenticated users to bypass authorization checks and view unauthorized information ...

Feb 10, 2026
CVE-2026-24326
4.3

This vulnerability in SAP S/4HANA Defense & Security allows authenticated users with standard privileges to directly modify database tables through re...

Feb 10, 2026
CVE-2026-23688
4.3

This vulnerability in SAP Fiori App Manage Service Entry Sheets allows authenticated users to perform unauthorized actions due to missing authorizatio...

Feb 10, 2026
CVE-2026-23681
4.3

This vulnerability in SAP Support Tools Plug-In allows authenticated users to access system configuration information without proper authorization che...

Feb 10, 2026
CVE-2026-2208
4.3

This CVE describes a missing authorization vulnerability in WeKan's Rules Handler component that allows unauthorized access to functionality. Attacker...

Feb 8, 2026
CVE-2025-15476
4.3

The Bucketlister WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to add, de...

Feb 7, 2026
CVE-2025-15326
4.3

CVE-2025-15326 is an improper access controls vulnerability in Tanium Patch that allows authenticated users to access or modify resources beyond their...

Feb 5, 2026
CVE-2025-15327
4.3

CVE-2025-15327 is an improper access controls vulnerability in Tanium Deploy that could allow authenticated users to perform unauthorized actions. Thi...

Feb 5, 2026
CVE-2025-13416
4.3

This vulnerability in the ProfileGrid WordPress plugin allows authenticated users with Subscriber-level access or higher to suspend arbitrary users fr...

Feb 5, 2026
CVE-2026-1897
4.3

This CVE describes a missing authorization vulnerability in WeKan's position history tracking component. Attackers can exploit this remotely to access...

Feb 5, 2026
CVE-2026-25020
4.3

This CVE describes a Missing Authorization vulnerability in the WP Sync for Notion WordPress plugin that allows attackers to exploit incorrectly confi...

Feb 3, 2026
CVE-2026-25011
4.3

This CVE describes a missing authorization vulnerability in the WP Custom Admin Interface WordPress plugin that allows attackers to exploit incorrectl...

Feb 3, 2026
CVE-2026-25016
4.3

This CVE describes a Missing Authorization vulnerability in the Nelio Popups WordPress plugin that allows attackers to exploit incorrectly configured ...

Feb 3, 2026
CVE-2026-24995
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Latest Post Shortcode plugin that allows attackers to exploit incorrectly co...

Feb 3, 2026
CVE-2026-24996
4.3

This CVE describes a Missing Authorization vulnerability in the WPElemento Importer WordPress plugin that allows attackers to exploit incorrectly conf...

Feb 3, 2026
CVE-2026-24985
4.3

This CVE describes a Missing Authorization vulnerability in the WP Forms Signature Contract Add-On for WordPress. It allows attackers to exploit incor...

Feb 3, 2026
CVE-2026-24951
4.3

This CVE describes a Missing Authorization vulnerability in the myCred WordPress plugin that allows attackers to exploit incorrectly configured access...

Feb 3, 2026
CVE-2026-24965
4.3

This CVE describes a Missing Authorization vulnerability in the Contest Gallery WordPress plugin that allows attackers to exploit incorrectly configur...

Feb 3, 2026
CVE-2026-24939
4.3

This CVE describes a Missing Authorization vulnerability in the Modula Image Gallery WordPress plugin that allows attackers to exploit incorrectly con...

Feb 3, 2026
CVE-2026-24940
4.3

This CVE describes a missing authorization vulnerability in the Travelfic Toolkit WordPress plugin that allows attackers to exploit incorrectly config...

Feb 3, 2026
CVE-2026-24947
4.3

This CVE describes a missing authorization vulnerability in LA-Studio Element Kit for Elementor WordPress plugin that allows attackers to exploit inco...

Feb 3, 2026
CVE-2026-24588
4.3

This CVE describes a missing authorization vulnerability in the Smart Product Viewer WordPress plugin that allows attackers to exploit incorrectly con...

Jan 23, 2026
CVE-2026-24571
4.3

This CVE describes a Missing Authorization vulnerability in the BOX NOW Delivery WordPress plugin that allows attackers to bypass access controls. It ...

Jan 23, 2026
CVE-2026-24578
4.3

This vulnerability allows attackers to bypass authorization controls in the WordPress Admin Login URL Change plugin, potentially accessing administrat...

Jan 23, 2026
CVE-2026-24579
4.3

This CVE describes a Missing Authorization vulnerability in the WP Messiah Ai Image Alt Text Generator for WordPress plugin. It allows attackers to ex...

Jan 23, 2026
CVE-2026-24580
4.3

This CVE describes a Missing Authorization vulnerability in the Ecwid Shopping Cart WordPress plugin that allows attackers to bypass access controls. ...

Jan 23, 2026
CVE-2026-24567
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Anything Order by Terms plugin that allows attackers to exploit incorrectly ...

Jan 23, 2026
CVE-2026-24569
4.3

This CVE describes a missing authorization vulnerability in the WordPress Media Library File Size plugin that allows attackers to exploit incorrectly ...

Jan 23, 2026
CVE-2026-24563
4.3

This CVE describes a missing authorization vulnerability in the LifePress WordPress plugin that allows attackers to bypass access controls. It affects...

Jan 23, 2026
CVE-2026-24543
4.3

This CVE describes a Missing Authorization vulnerability in the Materialis Companion WordPress plugin that allows attackers to exploit incorrectly con...

Jan 23, 2026
CVE-2026-24544
4.3

This CVE describes a Missing Authorization vulnerability in the HD Quiz WordPress plugin that allows attackers to bypass access controls. Attackers ca...

Jan 23, 2026
CVE-2026-24532
4.3

This CVE describes a Missing Authorization vulnerability in the SiteLock Security WordPress plugin that allows attackers to bypass access controls. At...

Jan 23, 2026
CVE-2026-24535
4.3

This CVE describes a Missing Authorization vulnerability in the WordPress Automatic Featured Images from Videos plugin. It allows attackers to exploit...

Jan 23, 2026
CVE-2026-24522
4.3

This CVE describes a Missing Authorization vulnerability in the MyThemeShop WP Subscribe WordPress plugin (wp-subscribe) that allows attackers to expl...

Jan 23, 2026
CVE-2025-13921
4.3

The weDocs WordPress plugin has a missing capability check vulnerability that allows authenticated users with Subscriber-level access or higher to edi...

Jan 23, 2026
CVE-2026-24386
4.3

This CVE describes a Missing Authorization vulnerability in the Element Invader WordPress plugin that allows unauthorized users to access functionalit...

Jan 22, 2026
CVE-2026-24387
4.3

This CVE describes a missing authorization vulnerability in the WP Quick Post Duplicator WordPress plugin that allows attackers to exploit incorrectly...

Jan 22, 2026
CVE-2026-24388
4.3

This CVE describes a Missing Authorization vulnerability in the WPMasterToolKit WordPress plugin that allows attackers to bypass access controls. It a...

Jan 22, 2026
CVE-2026-22466
4.3

This CVE describes a missing authorization vulnerability in the WP MapIt WordPress plugin that allows attackers to bypass access controls. It affects ...

Jan 22, 2026
CVE-2026-22468
4.3

This CVE describes a Missing Authorization vulnerability in the Absolute Addons For Elementor WordPress plugin that allows attackers to exploit incorr...

Jan 22, 2026
CVE-2026-22450
4.3

This CVE describes a Missing Authorization vulnerability in the Select-Themes Don Peppe WordPress theme that allows attackers to exploit incorrectly c...

Jan 22, 2026
CVE-2026-0554
4.3

The NotificationX WordPress plugin has a missing capability check vulnerability in REST API endpoints that allows authenticated users with Contributor...

Jan 20, 2026
CVE-2026-23721
4.3

OpenProject versions before 17.0.1 and 16.6.5 have an information disclosure vulnerability where users with View Members permission in any project can...

Jan 19, 2026
CVE-2025-12168
4.3

The Phrase TMS Integration for WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or hig...

Jan 17, 2026
CVE-2026-1003
4.3

The GetGenie WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Author-level permissions or higher to del...

Jan 16, 2026
CVE-2025-14982
4.3

The Booking Calendar plugin for WordPress has a missing authorization vulnerability that allows authenticated users with Subscriber-level access or hi...

Jan 16, 2026

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,064 CVEs classified as CWE-862, with 229 rated critical and 867 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free