In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with
In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission chec
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with n
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with
In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credent
In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permiss
In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalati
A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 th
Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that
In Boa, there is a possible information disclosure due to a missing permission check. This could lead to remote informat
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configur
The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerabil
The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability
The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPad
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing cap
The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisti
The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on th
Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to downlo
A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experi
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incor
In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can
VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagno
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain t
1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file wr
In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capabi
The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit
The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to ver
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, all
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to re
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outsi
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful explo
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can d
In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensi
The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started