OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a secur
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development.
Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopbac
Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows S
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Af
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative action
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several
U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP
DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user wa
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killp
The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_
Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.
SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authe
Yappli is an application development platform which provides the function to access a requested URL using Custom URL Sch
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the aff
The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and
In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan resul
In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to
In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony setting
In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connecti
In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast
In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local esc
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not p
In memory management driver, there is a possible escalation of privilege due to a missing permission check. This could l
In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could l
In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission by
In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing perm
In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user co
In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL h
An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrar
An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to exec
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious appli
In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROF
In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission c
In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a mis
In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check.
In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection
In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, with
In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connec
In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing perm
In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not proper
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.2312
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started