ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder AP
In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has u
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the Syst
An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attacker
A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission
A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to co
A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domai
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execu
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMC
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due t
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options v
SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authent
Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access
The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to
SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, r
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attack
Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing use
The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action
Affected devices do not properly authorize the change password function of the web interface. This could allow low priv
Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not prope
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request.
The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external Post
Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exp
OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup sub
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retriev
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce
Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks whe
An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken A
Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server witho
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /sho
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /sho
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to a
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing non
A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission t
The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which cou
In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead
In system service, there is a possible permission bypass due to a missing permission check. This could lead to local esc
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider co
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started