A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Aff
A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to
The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing
The Indeed Membership Pro plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on
The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions
The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and incl
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request For
The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to
The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing
The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a
Missing Authorization vulnerability in fifu.App Featured Image from URL allows Exploiting Incorrectly Configured Access
Missing Authorization vulnerability in solwin User Activity Log Pro allows Exploiting Incorrectly Configured Access Cont
Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Se
Missing Authorization vulnerability in Ahmed Kaludi, Mohammed Kaludi AMP for WP allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in Presto Made, Inc Presto Player allows Exploiting Incorrectly Configured Access Co
Missing Authorization vulnerability in TotalSuite Total Poll Lite allows Exploiting Incorrectly Configured Access Contro
Missing Authorization vulnerability in Muhammad Rehman Remove Duplicate Posts allows Exploiting Incorrectly Configured A
Missing Authorization vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter.This issue affec
Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly C
Permission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause f
The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an
Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allow
'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable t
Missing Authorization vulnerability in dreamfox Dreamfox Media Payment gateway per Product for Woocommerce woocommerce-p
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import e
Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged
The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due
Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Accessing Func
The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources,
In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing pe
In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission ch
This issue was addressed with improved file handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, m
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ve
In the Linux kernel, the following vulnerability has been resolved: parisc: BTLB: Fix crash when setting up BTLB at CPU
In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service wit
SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalati
SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access level
Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Secur
The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is
Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode,
The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification
Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooCommerce Migration.This issue affects Cart2C
Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pic
Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8.
Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5
Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyTh
Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Port
Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a th
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started