Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty term
In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due t
In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass.
In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local
In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escala
In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Priv
In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local e
A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is explo
Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0,
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Manageme
Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Expl
OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab rou
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser
OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP fronten
HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call de
A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows auth
Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects
Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpo
Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configu
Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting I
Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorre
Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Ac
Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in staviravn AIO WP Builder all-in-one-wp-builder allows Exploiting Incorrectly Conf
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares per
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model override
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 unti
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose
OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} acc
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access a
The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the
The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLH
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started