Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress.
Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which
Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and de
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allo
Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start em
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in
In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing
Article template contents with sensitive data could be accessed from agents without permissions.
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content provide
In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. T
In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing pe
In ContentService, there is a possible disclosure of available account types due to a missing permission check. This cou
In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check.
In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check.
In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could l
In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a mi
In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. T
In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a miss
In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to
In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the ba
Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.
In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a
In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest mode due to a missin
In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mode due to a missing p
In createDialog of WifiScanModeActivity.java, there is a possible way for a Guest user to enable location-sensitive sett
In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a n
In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission che
An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk la
An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 1
A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problemati
In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in
In LocationManager, there is a possible way to get location information due to a missing permission check. This could le
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a miss
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionali
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val
An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAj
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb
VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthori
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code v
A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can acc
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerabilit
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when access
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started