Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly
Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback
Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Se
Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Leve
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file a
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is a
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loadi
The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing
A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged atta
The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unau
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is
A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all ver
The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that
The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin inst
The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data
Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identi
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the t
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with a
OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allow
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension componen
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scrip
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some su
Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploit
Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Con
Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encrypti
Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoi
Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are a
SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the pu
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
Missing Authorization vulnerability in Theme-one The Grid the-grid allows Exploiting Incorrectly Configured Access Contr
Missing Authorization vulnerability in wp-configurator WP Configurator Pro wp-configurator-pro allows Exploiting Incorre
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started