JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API wi
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authen
The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) with
MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html.
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or de
The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and includi
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In af
Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request i
A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with t
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command
The vulnerability exists in Syska SW100 Smartwatch due to an improper implementation and/or configuration of Nordic Devi
Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attacker
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions a
The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be d
In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due
In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starti
In firewall service, there is a missing permission check. This could lead to local escalation of privilege with system e
In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and unins
In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks
In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis
In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin
Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This
In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due
In phoneEx service, there is a possible missing permission check. This could lead to local escalation of privilege with
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no
.In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In powerEx service, there is a possible missing permission check. This could lead to local escalation of privilege with
Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attacker
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit
In dialer service, there is a possible missing permission check. This could lead to local escalation of privilege with n
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started