Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as
Flarum is a discussion platform for websites. If the first post of a discussion is permanently deleted but the discussio
Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9.
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 1
A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps,
In mnld, there is a possible leak of GPS location due to a missing permission check. This could lead to local informatio
In music service, there is a missing permission check. This could lead to local information disclosure with no additiona
In music service, there is a missing permission check. This could lead to local information disclosure with no additiona
The com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with n
Missing Authorization in GitHub repository hamza417/inure prior to Build95.
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a te
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affecte
Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zu
Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able t
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.
Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12.
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an
Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, S
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s v
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could all
Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any us
Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers w
Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner&#
Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting wit
Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action,
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does no
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client a
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 all
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger build
A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a m
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbi
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to c
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Pr
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public cl
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentic
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitiv
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized acc
LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or
Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account.
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started