A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read
A missing permission check in Jenkins Fogbugz Plugin 2.2.17 and earlier allows attackers with Item/Read permission to tr
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in part
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Pr
The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
Operation restriction bypass vulnerability in Message and Bulletin of Cybozu Garoon 4.6.0 to 5.9.2 allows a remote authe
The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Setting Changs in versions up to, and including, 5.5.
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t
The WooCommerce Multi Currency plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inclu
The FlyingPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX
The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '
The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action i
The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capabili
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including,
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability
The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to unauthorized modification of
The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of d
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of d
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of d
The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c
The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the
The WP Activity Log Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to
Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post
When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated
Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an an
The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capabil
The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including,
The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o
The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing cap
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attack
A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to en
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capabili
An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrar
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not
The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a
A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to
The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on
The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a
The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capabili
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started