Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 10/188
7.8
CVE-2026-42851

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty term

7.8
CVE-2026-0133

In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due t

7.8
CVE-2025-48617

In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass.

7.8
CVE-2026-0071

In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local

7.8
CVE-2026-0081

In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escala

7.8
CVE-2026-28615

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead

7.8
CVE-2026-6509

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Priv

7.8
CVE-2026-20495

In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local e

7.8
CVE-2026-66109

A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is explo

7.7
CVE-2026-23477

Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0,

7.7
CVE-2026-24322

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f

7.7
CVE-2026-32131

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Manageme

7.7
CVE-2026-32441

Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Expl

7.7
CVE-2026-42436

OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab rou

7.7
CVE-2026-43573

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser

7.7
CVE-2026-43580

OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat

7.7
CVE-2026-46518

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio

7.7
CVE-2026-49821

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

7.7
CVE-2026-49822

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

7.7
CVE-2026-54322

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1

7.7
CVE-2026-55189

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP fronten

7.7
CVE-2026-14373

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host

7.7
CVE-2026-59216

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call de

7.7
CVE-2026-14251

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when

7.7
CVE-2026-53514

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when

7.7
CVE-2026-13078

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered

7.7
CVE-2026-20483

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local es

7.7
CVE-2026-74869

stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows auth

7.7
CVE-2026-71307

Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only

7.7
CVE-2026-56707

Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects

7.7
CVE-2026-82242

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpo

7.6
CVE-2025-67967

Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configu

7.6
CVE-2025-68057

Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting I

7.6
CVE-2025-68058

Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorre

7.6
CVE-2025-68059

Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Ac

7.6
CVE-2025-69311

Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured

7.6
CVE-2025-53217

Missing Authorization vulnerability in staviravn AIO WP Builder all-in-one-wp-builder allows Exploiting Incorrectly Conf

7.6
CVE-2026-33918

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio

7.6
CVE-2026-40474

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares per

7.6
CVE-2026-44555

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open

7.6
CVE-2026-49374

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

7.6
CVE-2026-62186

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model override

7.6
CVE-2026-52870

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 unti

7.6
CVE-2026-55544

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose

7.6
CVE-2026-67527

OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} acc

7.6
CVE-2026-67621

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf

7.6
CVE-2026-73326

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access a

7.6
CVE-2026-72669

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the

7.6
CVE-2026-72825

The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/

7.6
CVE-2026-69189

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLH

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started