In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system
In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalati
In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission che
In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege wit
In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege wit
In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. T
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalati
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affecte
Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permis
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overal
A missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers with
A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permis
A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to c
A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission t
wire-server provides back end services for Wire, a team communication and collaboration platform. Prior to version 2022-
The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability che
WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and ass
In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1
SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be di
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to
The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with ro
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities whic
Jenkins OctoPerf Load Testing Plugin Plugin 4.5.1 and earlier does not perform a permission check in a connection test H
The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when
The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when c
A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission
A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to t
The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before disp
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker posse
Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBa
A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gat
In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special pa
The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Acti
The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on th
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up t
The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on
The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability ch
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a m
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a m
A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with O
Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary po
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Educatio
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables
When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started