In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain acce
An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a
There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive
There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attacke
A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could al
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.
Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGu
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing
The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including
Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect in
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up
The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensu
Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally all
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API com
The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and includin
The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up t
Improper access control vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user of the PC whe
The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and in
The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vu
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that
The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions p
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in u
A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions
The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o
The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP
An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface
SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users ar
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows att
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missi
metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability
The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and incl
Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Repla
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a securit
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, pr
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail
Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messa
Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started