Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 148/188
7.8
CVE-2023-42694

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42695

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42696

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with

7.8
CVE-2023-42736

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with

7.8
CVE-2023-42738

In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with

7.8
CVE-2023-42739

In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission

7.8
CVE-2023-42740

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission chec

7.8
CVE-2023-42743

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with

7.8
CVE-2023-42745

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with

7.8
CVE-2023-42746

In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42747

In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with n

7.8
CVE-2023-42748

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with

7.8
CVE-2023-40089

In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credent

7.8
CVE-2023-40094

In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permiss

7.8
CVE-2023-48402

In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalati

7.7
CVE-2023-3442

A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 th

7.7
CVE-2023-43700

Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that

7.5
CVE-2021-31576

In Boa, there is a possible information disclosure due to a missing permission check. This could lead to remote informat

7.5
CVE-2022-48166

An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configur

7.5
CVE-2022-48302

The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerabil

7.5
CVE-2022-48350

The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability

7.5
CVE-2023-27963

The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPad

7.5
CVE-2023-33252

iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less

7.5
CVE-2023-2480

Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation

7.5
CVE-2020-36696

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing cap

7.5
CVE-2021-4339

The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisti

7.5
CVE-2021-4348

The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export

7.5
CVE-2021-4355

The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on th

7.5
CVE-2023-3230

Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.

7.5
CVE-2023-36144

An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to downlo

7.5
CVE-2023-30586

A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experi

7.5
CVE-2023-35940

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incor

7.5
CVE-2023-30195

In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can

7.5
CVE-2023-20899

VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagno

7.5
CVE-2023-3714

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec

7.5
CVE-2023-37860

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain t

7.5
CVE-2023-39966

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file wr

7.5
CVE-2023-33915

In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no

7.5
CVE-2022-4943

The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capabi

7.5
CVE-2023-5132

The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit

7.5
CVE-2023-5426

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa

7.5
CVE-2023-46352

In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to ver

7.5
CVE-2023-5454

The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, all

7.5
CVE-2023-6038

A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to re

7.5
CVE-2023-6020

LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.

7.5
CVE-2023-30581

The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outsi

7.5
CVE-2023-44113

Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful explo

7.5
CVE-2023-46354

In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can d

7.5
CVE-2023-39167

In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensi

7.5
CVE-2023-5949

The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started