Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 149/188
7.5
CVE-2023-51650

Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration i

7.4
CVE-2022-21953

A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod a

7.4
CVE-2023-1299

HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using worklo

7.4
CVE-2023-2757

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability

7.4
CVE-2023-33983

The Introduction Client in Briar through 1.5.3 does not implement out-of-band verification for the public keys of introd

7.4
CVE-2020-36715

The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on se

7.4
CVE-2023-0456

A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token fro

7.4
CVE-2023-6394

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission spe

7.3
CVE-2023-22478

KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. T

7.3
CVE-2022-4940

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to

7.3
CVE-2020-36697

The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up

7.3
CVE-2020-36716

The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the

7.3
CVE-2023-36815

Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is

7.3
CVE-2023-2078

The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data

7.3
CVE-2023-6007

The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to

7.2
CVE-2023-26035

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and An

7.2
CVE-2021-4350

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and in

7.2
CVE-2023-0291

The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the

7.1
CVE-2023-27264

A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugi

7.1
CVE-2023-32311

CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organ

7.1
CVE-2023-32316

CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organiz

7.1
CVE-2020-36720

The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.

7.1
CVE-2023-37949

A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read perm

7.1
CVE-2023-37965

A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permissi

7.1
CVE-2023-2268

Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users.

7.1
CVE-2023-5165

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via t

7.1
CVE-2023-44211

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr

7.1
CVE-2023-44212

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr

7.1
CVE-2023-45244

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr

7.1
CVE-2023-45246

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr

7.1
CVE-2023-45247

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr

7.1
CVE-2023-48676

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr

6.8
CVE-2023-22488

Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private co

6.8
CVE-2020-22007

OS Command Injection vulnerability in OKER G955V1 v1.03.02.20161128, allows physical attackers to interrupt the boot seq

6.8
CVE-2023-20926

In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due t

6.8
CVE-2023-21132

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss

6.8
CVE-2023-21133

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss

6.8
CVE-2023-21134

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss

6.8
CVE-2023-21140

In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a miss

6.8
CVE-2023-5056

A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that woul

6.7
CVE-2022-39081

In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex

6.7
CVE-2022-39082

In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex

6.7
CVE-2022-39083

In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex

6.7
CVE-2022-39084

In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex

6.7
CVE-2022-39085

In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex

6.7
CVE-2022-39086

In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex

6.7
CVE-2022-39087

In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex

6.7
CVE-2022-39088

In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex

6.7
CVE-2022-47339

In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalat

6.7
CVE-2022-47341

In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with sys

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started