In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import wit
Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Con
The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca
In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from t
SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalati
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommende
Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of pri
Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedI
Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control S
Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Cont
In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a
In multiple functions of healthconnect, there is a possible leakage of exercise route data due to a missing permission c
When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting
A vulnerability classified as problematic has been found in Totara LMS up to 18.7. This affects an unknown part of the c
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database u
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query par
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control
Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/transl
Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logge
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check
Missing Authorization vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Exploiting Incorrectly Conf
Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues wher
An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricte
The issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.1, ma
SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. T
Missing Authentication for Critical Function, Missing Authorization vulnerability in Yordam Information Technology Mobil
** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-
Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows
Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby,
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL autho
The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in version
The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and inc
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on severa
In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalat
Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye:
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0,
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. Thi
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activ
The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missi
The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions
The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and incl
The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th
The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to
The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, a
The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of thei
Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclo
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started