A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affecte
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation A
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting fr
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting
SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASI
Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skyl
A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on
The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW
In Ifaa service, there is a possible missing permission check. This could lead to local denial of service with System ex
In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local inform
In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System exe
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission chec
In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with
The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a te
The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capab
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authen
The My YouTube Channel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t
A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers with Overall/Read perm
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overal
A missing permission check in Jenkins Cisco Spark Notifier Plugin 1.1.1 and earlier allows attackers with Overall/Read p
The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ens
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overa
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permis
A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read perm
The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check
The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13.
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a mi
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missi
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing cap
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a mi
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missi
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when
A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers with Overal
A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability ch
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability ch
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on t
SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticat
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started