Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 13/188
7.5
CVE-2026-34886

Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.

7.5
CVE-2026-34898

Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.

7.5
CVE-2026-39503

Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.

7.5
CVE-2026-39513

Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.

7.5
CVE-2026-39524

Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.

7.5
CVE-2026-39533

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.

7.5
CVE-2026-39534

Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.

7.5
CVE-2026-40741

Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.

7.5
CVE-2026-40774

Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.

7.5
CVE-2026-40776

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.

7.5
CVE-2026-42666

Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.

7.5
CVE-2026-48835

Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.

7.5
CVE-2026-48873

Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.

7.5
CVE-2026-48883

Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.

7.5
CVE-2026-49070

Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.

7.5
CVE-2025-68045

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

7.5
CVE-2026-39490

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

7.5
CVE-2026-52711

Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.

7.5
CVE-2025-69103

Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions.

7.5
CVE-2026-49057

Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.

7.5
CVE-2026-54802

Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.

7.5
CVE-2026-54810

Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control S

7.5
CVE-2026-11912

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization

7.5
CVE-2026-56341

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authori

7.5
CVE-2026-9178

The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,

7.5
CVE-2026-52799

Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file

7.5
CVE-2026-27366

Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.

7.5
CVE-2026-54828

Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

7.5
CVE-2026-54830

Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.

7.5
CVE-2026-54844

Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.

7.5
CVE-2026-54832

Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.

7.5
CVE-2026-54835

Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.

7.5
CVE-2026-54837

Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions.

7.5
CVE-2026-54846

Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.

7.5
CVE-2026-54847

Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.

7.5
CVE-2026-56025

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

7.5
CVE-2026-56061

Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.

7.5
CVE-2026-47193

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint

7.5
CVE-2026-54475

Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Cl

7.5
CVE-2026-13468

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization

7.5
CVE-2026-1239

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access

7.5
CVE-2025-69134

Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.

7.5
CVE-2026-39448

Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.

7.5
CVE-2026-25038

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

7.5
CVE-2026-59708

The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeU

7.5
CVE-2026-5356

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input

7.5
CVE-2026-56250

Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST,

7.5
CVE-2026-54695

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1

7.5
CVE-2026-15291

The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all

7.5
CVE-2026-56279

Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that rema

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started