Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 146/188
8.2
CVE-2023-43652

JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API wi

8.2
CVE-2023-30969

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authen

8.1
CVE-2023-0555

The Quick Restaurant Menu plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o

8.1
CVE-2022-45636

An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) with

8.1
CVE-2023-27701

MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html.

8.1
CVE-2023-25552

A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or de

8.1
CVE-2023-2545

The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che

8.1
CVE-2021-4383

The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and includi

8.1
CVE-2023-34463

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In af

8.1
CVE-2023-38510

Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request i

8.1
CVE-2023-39438

A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CL

8.1
CVE-2023-37910

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with t

8.1
CVE-2023-4606

An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command

8.1
CVE-2022-3007

The vulnerability exists in Syska SW100 Smartwatch due to an improper implementation and/or configuration of Nordic Devi

8.1
CVE-2023-43885

Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attacker

8.1
CVE-2023-48222

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions a

7.9
CVE-2023-43488

The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be d

7.8
CVE-2023-20912

In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due

7.8
CVE-2023-20916

In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starti

7.8
CVE-2022-47361

In firewall service, there is a missing permission check. This could lead to local escalation of privilege with system e

7.8
CVE-2023-20955

In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and unins

7.8
CVE-2023-20959

In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks

7.8
CVE-2023-21001

In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings

7.8
CVE-2023-21002

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis

7.8
CVE-2023-21003

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis

7.8
CVE-2023-21004

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis

7.8
CVE-2023-21005

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis

7.8
CVE-2023-21015

In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis

7.8
CVE-2023-21021

In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin

7.8
CVE-2023-26269

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This

7.8
CVE-2023-21094

In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due

7.8
CVE-2022-44433

In phoneEx service, there is a possible missing permission check. This could lead to local escalation of privilege with

7.8
CVE-2022-48243

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48244

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48245

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48246

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48247

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48248

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48249

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48250

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48368

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48369

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48383

.In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48384

In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2022-48388

In powerEx service, there is a possible missing permission check. This could lead to local escalation of privilege with

7.8
CVE-2023-31826

Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attacker

7.8
CVE-2022-48390

In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit

7.8
CVE-2022-48392

In dialer service, there is a possible missing permission check. This could lead to local escalation of privilege with n

7.8
CVE-2023-30863

In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege

7.8
CVE-2023-30864

In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started