Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Request
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized
The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification
Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Qua
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported version
The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider
The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider
A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected
Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Acces
The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable
Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly
The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovere
In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injectio
Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated atta
In the Linux kernel, the following vulnerability has been resolved: media: rc: bpf attach/detach requires write permiss
Ant Media Server is live streaming engine software. A local privilege escalation vulnerability in present in versions 2.
In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due t
In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to
In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing
A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited,
A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to
In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could
In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is pro
In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local esca
In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due
In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a mi
In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled access
In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to an
In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission
In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missin
In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permi
In the development options section of the Settings app, there is a possible authentication bypass due to a missing permi
The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client va
In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check
An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers
Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289
Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-92
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vu
Missing Authorization vulnerability in Joris van Montfort JVM rich text icons.This issue affects JVM rich text icons: fr
Missing Authorization vulnerability in Undsgn Uncode Core.This issue affects Uncode Core: from n/a through 2.8.8.
Missing Authorization vulnerability in PressFore Rolo Slider.This issue affects Rolo Slider: from n/a through 1.0.9.
Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of p
Missing Authorization vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Exploiting
Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized
Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue aff
Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: fr
Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder:
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started