Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and ear
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (D
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 doe
The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpe
A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s):
The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated us
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploade
The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earli
WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a n
Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au
An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior t
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to exec
Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infecte
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with hi
A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modificatio
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuratio
TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could ex
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability
In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to lo
There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located impro
Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convin
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escala
An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (wit
The developer page about:memory has a Measure function for exploring what object types the browser has allocated and the
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users exter
A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Re
Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerabili
SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allo
The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to rea
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions funct
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potent
The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing a
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrie
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to us
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possibl
The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started