#Missing Authorization
All CosmicBytez Labs articles tagged #Missing Authorization, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-101000: Missing Authorization in Netcore NBR100V2 ACL Handler
Netcore NBR100V2's ACL handler skips authorization on uci.apply, letting unauthenticated attackers tamper with device configuration remotely.
- Security
Malcure Malware Shield Missing Authorization Enables Multisite File Write (CVE-2026-96896)
Malcure Malware Shield lacks an auth check on an AJAX action, letting subsite admins write or delete files network-wide on multisite.
- Security
CVE-2026-81648: Unauthenticated Authorization Bypass in CryptoPayment Gateway WordPress Plugin
CVSS 10 flaw in CryptoPayment Gateway (≤ 1.2.2) lets anyone delete files, overwrite config, and steal cleartext wallet keys via an open AJAX endpoint.
- Security
Missing Authorization in WWBN AVideo Exposes Scheduler Email Jobs
CVE-2026-90537 lets an attacker with a harvested daily token enumerate AVideo scheduler jobs, read private data, and trigger email sends.
- Security
CVE-2026-12645 & CVE-2026-12646: Ivanti Neurons for ITSM Missing-Authorization RCE Flaws
Two CVSS 9.9 missing-authorization bugs in Ivanti Neurons for ITSM let any authenticated user run code on the server. On-prem admins must patch.
- Security
AI Website Builder WordPress Plugin: Unauthenticated RCE via Missing Authorization
CVE-2026-82923 lets unauthenticated attackers write arbitrary files, install plugins, and wipe content on sites running the GitHub build of AI Website Builder.
- Security
CVE-2026-16149: Security Hardener WordPress Plugin Bypasses All REST API Authorization
Security Hardener plugin up to 2.4.4 overwrites REST endpoint permissions via rest_endpoints filter, bypassing all registered auth callbacks.
- Security
CVE-2026-14365: TrueBooker WordPress Plugin Authorization Bypass Enables Unauthenticated Password Change
A second critical flaw in the TrueBooker Appointment Booking WordPress plugin allows unauthenticated attackers to change the password of any user,...
- Security
CVE-2026-15397: Missing Authorization in Subscriptions for WooCommerce Plugin
A missing authorization vulnerability in the Subscriptions for WooCommerce plugin allows authenticated users with minimal privileges to perform...
- Security
CVE-2025-10656: WooCommerce Plugin Missing Authorization Allows Unauthenticated Admin Account Creation
A critical missing authorization vulnerability in the Spreadsheet Price Changer for WooCommerce plugin allows unauthenticated attackers to create admin...
- Security
CVE-2026-53469: migration-planner Missing Authorization on Bulk Delete
A critical missing authorization vulnerability (CVSS 9.1) in Red Hat's migration-planner allows any authenticated user to send a DELETE request to...
- Security
CVE-2018-25391: HaPe PKH 1.1 Unauthenticated Record Deletion via Missing Authorization
HaPe PKH 1.1, a PHP-based web application, fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to...
- Security
Critical Auth Bypass in InfusedWoo Pro Enables
A CVSS 9.1 authorization bypass in InfusedWoo Pro for WordPress lets unauthenticated attackers permanently delete arbitrary data across all installations...
- Security
Critical RCE in Hitachi Vantara Pentaho via Unrestricted
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 fail to restrict Groovy scripts in PRPT reports, allowing privileged users...