Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 164/188
7.8
CVE-2022-39091

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39092

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39093

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39094

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39095

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39096

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39097

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39098

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39099

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39100

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39101

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-39102

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-42776

In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no addit

7.8
CVE-2022-42777

In power management service, there is a missing permission check. This could lead to set up power management service wit

7.8
CVE-2022-42778

In windows manager service, there is a missing permission check. This could lead to set up windows manager service with

7.8
CVE-2022-20503

In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration du

7.8
CVE-2022-20506

In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of priv

7.8
CVE-2022-20508

In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a per

7.8
CVE-2022-20522

In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of priv

7.8
CVE-2022-20547

In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing per

7.5
CVE-2021-24831

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users,

7.5
CVE-2022-0236

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data d

7.5
CVE-2021-38789

Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the c

7.5
CVE-2021-24906

The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file,

7.5
CVE-2022-23945

Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

7.5
CVE-2021-25093

The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauth

7.5
CVE-2021-24839

The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX acti

7.5
CVE-2022-24317

A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a spe

7.5
CVE-2021-25087

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpo

7.5
CVE-2021-3814

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session aut

7.5
CVE-2022-27658

Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could

7.5
CVE-2022-27480

A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V

7.5
CVE-2022-27669

An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - v

7.5
CVE-2021-25002

The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which co

7.5
CVE-2022-1442

The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/c

7.5
CVE-2022-30746

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely

7.5
CVE-2022-32560

An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.

7.5
CVE-2022-33913

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php w

7.5
CVE-2021-33057

The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCE

7.5
CVE-2022-36883

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds o

7.5
CVE-2022-2379

The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated us

7.5
CVE-2022-36024

py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to r

7.5
CVE-2022-38370

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal

7.5
CVE-2022-36091

XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature,

7.5
CVE-2022-2987

The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF

7.5
CVE-2021-28052

A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorizati

7.5
CVE-2022-44549

The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause thi

7.5
CVE-2022-45385

A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthe

7.5
CVE-2022-41930

org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged

7.5
CVE-2022-24190

The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The us

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started