The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_p
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in
Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an a
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoin
The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extens
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi
A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permiss
The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's setti
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugi
Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin setting
The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.
Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could expl
Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could
Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attac
In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access inf
SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messag
The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and
The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching boo
The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting
An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this
A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenti
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information a
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing u
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to bo
The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticate
The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /reg
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files f
The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its sett
A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not vali
The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom
A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds o
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services
PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem ac
Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary priv
Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and de
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started