Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, all
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 i
Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interacti
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi setti
A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users
Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2loc
Missing Authorization in Packagist librenms/librenms prior to 22.2.0.
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 1
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to inte
The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_s
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged a
In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalati
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint'
It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect
Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disab
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch
Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" f
In multiple locations of DreamManagerService.java, there is a missing permission check. This could lead to local escalat
In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to a missing permission ch
A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access
An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting f
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJA
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX act
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads t
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission
Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX a
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with t
Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overal
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overal
Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attacke
A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Re
Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro ve
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option me
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing att
Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers wit
A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to conn
The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its set
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started