Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 151/188
6.5
CVE-2023-37944

A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to

6.5
CVE-2023-37953

A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to co

6.5
CVE-2023-37956

A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Re

6.5
CVE-2023-37959

A missing permission check in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers with Overall/Read pe

6.5
CVE-2023-37049

emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.

6.5
CVE-2022-43712

POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are n

6.5
CVE-2023-4124

Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.

6.5
CVE-2023-30950

The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint

6.5
CVE-2023-38508

Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edi

6.5
CVE-2023-41943

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowi

6.5
CVE-2023-43501

A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read

6.5
CVE-2022-36228

Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any dev

6.5
CVE-2023-4198

Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database tabl

6.5
CVE-2023-2448

The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '

6.5
CVE-2023-5386

The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability

6.5
CVE-2023-49620

Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (whi

6.4
CVE-2023-28640

Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an au

6.4
CVE-2021-4338

The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_r

6.3
CVE-2020-36670

The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to,

6.3
CVE-2022-4937

The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions

6.3
CVE-2021-4366

The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the

6.3
CVE-2023-2066

The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modifica

6.3
CVE-2023-35164

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In af

6.3
CVE-2023-4106

Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, res

6.3
CVE-2023-3999

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability c

6.3
CVE-2023-41046

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible

6.3
CVE-2023-46212

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionalit

6.2
CVE-2023-2788

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with adm

6.1
CVE-2023-39507

Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a

6.1
CVE-2023-4434

Missing Authorization in GitHub repository hamza417/inure prior to build88.

6.0
CVE-2023-35937

Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere

5.9
CVE-2023-38494

MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud ver

5.8
CVE-2021-4351

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and

5.8
CVE-2021-4369

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and

5.8
CVE-2023-5054

The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versi

5.7
CVE-2023-26510

Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsiste

5.7
CVE-2023-47870

Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross

5.5
CVE-2022-38678

In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service

5.5
CVE-2022-38682

In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service

5.5
CVE-2022-38683

In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service

5.5
CVE-2022-38684

In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service

5.5
CVE-2022-39104

In contacts service, there is a missing permission check. This could lead to local denial of service in Contacts service

5.5
CVE-2022-44422

In music service, there is a missing permission check. This could lead to local denial of service in contacts service wi

5.5
CVE-2022-44423

In music service, there is a missing permission check. This could lead to local denial of service in contacts service wi

5.5
CVE-2022-44424

In music service, there is a missing permission check. This could lead to local denial of service in contacts service wi

5.5
CVE-2022-44434

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic

5.5
CVE-2022-44435

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic

5.5
CVE-2022-44436

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic

5.5
CVE-2022-44437

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic

5.5
CVE-2022-44438

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts servic

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started