In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no addit
In power management service, there is a missing permission check. This could lead to set up power management service wit
In windows manager service, there is a missing permission check. This could lead to set up windows manager service with
In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration du
In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of priv
In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a per
In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of priv
In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing per
All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users,
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data d
Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the c
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file,
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauth
The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX acti
A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a spe
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpo
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session aut
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - v
The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which co
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/c
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php w
The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCE
A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds o
The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated us
py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to r
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature,
The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF
A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorizati
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause thi
A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthe
org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged
The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The us
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started