Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 15/188
7.5
CVE-2026-58434

Private Repository Metadata Remains Accessible After Access Revocation

7.5
CVE-2026-58438

Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot

7.5
CVE-2026-19728

The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is

7.5
CVE-2026-17087

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization

7.5
CVE-2026-16467

Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Pro

7.5
CVE-2026-16471

Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Prope

7.5
CVE-2026-11801

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and

7.5
CVE-2026-74904

SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (incl

7.5
CVE-2026-28567

Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.

7.5
CVE-2026-28571

Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.

7.5
CVE-2026-32472

Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.

7.5
CVE-2026-32549

Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.

7.5
CVE-2026-73377

Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.

7.5
CVE-2026-73994

Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.

7.5
CVE-2026-73385

Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.

7.5
CVE-2026-73394

Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.

7.5
CVE-2026-74020

Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.

7.5
CVE-2026-74021

Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.

7.5
CVE-2026-50222

Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's U

7.5
CVE-2026-77767

Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user ho

7.5
CVE-2026-28153

Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS,

7.5
CVE-2026-80191

GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated use

7.5
CVE-2026-74928

The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing

7.5
CVE-2026-78137

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthen

7.5
CVE-2026-80433

Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.

7.5
CVE-2026-81335

Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch

7.5
CVE-2026-75813

Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access

7.5
CVE-2026-81767

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

7.4
CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows s

7.4
CVE-2026-35561

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC drive

7.4
CVE-2026-62232

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FAS

7.4
CVE-2026-79286

Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to po

7.3
CVE-2025-69181

Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configu

7.3
CVE-2025-69184

Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorre

7.3
CVE-2025-69185

Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Ac

7.3
CVE-2025-69186

Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting I

7.3
CVE-2025-69187

Missing Authorization vulnerability in e-plugins Final User final-user allows Exploiting Incorrectly Configured Access C

7.3
CVE-2025-69188

Missing Authorization vulnerability in e-plugins fitness-trainer fitness-trainer allows Exploiting Incorrectly Configure

7.3
CVE-2025-69190

Missing Authorization vulnerability in e-plugins Listihub listihub allows Exploiting Incorrectly Configured Access Contr

7.3
CVE-2025-69191

Missing Authorization vulnerability in e-plugins ListingHub listinghub allows Exploiting Incorrectly Configured Access C

7.3
CVE-2025-69192

Missing Authorization vulnerability in e-plugins Real Estate Pro real-estate-pro allows Exploiting Incorrectly Configure

7.3
CVE-2025-69193

Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Ac

7.3
CVE-2026-0832

The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a

7.3
CVE-2025-68022

Missing Authorization vulnerability in soporteblue Plugin BlueX for WooCommerce bluex-for-woocommerce allows Exploiting

7.3
CVE-2025-68043

Missing Authorization vulnerability in LottieFiles LottieFiles lottiefiles allows Exploiting Incorrectly Configured Acce

7.3
CVE-2025-48634

In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. Th

7.3
CVE-2026-27396

Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Ac

7.3
CVE-2026-25456

Missing Authorization vulnerability in Aarsiv Groups Automated FedEx live/manual rates with shipping labels a2z-fedex-sh

7.3
CVE-2026-42377

Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Co

7.3
CVE-2026-9350

A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started