A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to
A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to co
A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Re
A missing permission check in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers with Overall/Read pe
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are n
Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.
The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edi
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowi
A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read
Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any dev
Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database tabl
The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (whi
Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an au
The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_r
The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to,
The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions
The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the
The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modifica
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In af
Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, res
The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability c
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionalit
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with adm
Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a
Missing Authorization in GitHub repository hamza417/inure prior to build88.
Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud ver
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and
The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versi
Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsiste
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service
In contacts service, there is a missing permission check. This could lead to local denial of service in Contacts service
In music service, there is a missing permission check. This could lead to local denial of service in contacts service wi
In music service, there is a missing permission check. This could lead to local denial of service in contacts service wi
In music service, there is a missing permission check. This could lead to local denial of service in contacts service wi
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started