The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectiv
A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 thr
An improper authorization vulnerability in Dremio Software allows authenticated users to delete arbitrary files that the
Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers t
Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in ve
Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted acc
A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoi
openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In ver
SunGrow's back end users system iSolarCloud https://isolarcloud.com uses an MQTT service to transport data from the us
HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in
A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which t
The Scratch Channel is a news website. If the user makes a fork, they can change the admins and make an article. Since t
The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provi
Vulnerability in the melis-core module of Melis Technology's Melis Platform, which, if exploited, allows an unauthentica
BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an
Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project.
MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-n
Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images
Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve pers
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even
A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files I
Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: fro
PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to
The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion
Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.T
Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vu
Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.
XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc
XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit ri
XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, an
XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extension
Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.
Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e
The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability che
The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliat
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions c
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress i
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the ge
Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload o
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner
Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary co
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypa
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These miss
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started