Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration i
A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod a
HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using worklo
The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability
The Introduction Client in Briar through 1.5.3 does not implement out-of-band verification for the public keys of introd
The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on se
A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token fro
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission spe
KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. T
The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to
The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up
The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the
Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data
The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and An
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and in
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugi
CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organ
CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organiz
The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.
A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read perm
A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permissi
Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.
Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via t
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private co
OS Command Injection vulnerability in OKER G955V1 v1.03.02.20161128, allows physical attackers to interrupt the boot seq
In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due t
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss
A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that woul
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalat
In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with sys
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started