A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without auth
The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow u
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior t
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231
This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical a
In netdiag, there is a possible information disclosure due to a missing permission check. This could lead to local infor
A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker
SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, re
A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote atta
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had per
Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTT
Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing fo
Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attac
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Re
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to tri
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not
SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authe
Improper access control vulnerability in Hot Pepper Gourmet App for Android ver.4.111.0 and earlier, and for iOS ver.4.1
Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authen
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to
Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attac
Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2
An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details
Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13
Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Plat
The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/
The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, whi
The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose proj
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchO
SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employe
The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and meta
snipe-it is vulnerable to Improper Access Control
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks
The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when upda
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC i
Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which co
Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects
In getSerialForPackage of DeviceIdentifiersPolicyService.java, there is a possible way to determine whether an app is in
In getOrganizationNameForUser of DevicePolicyManagerService.java, there is a possible organization name disclosure due t
In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine whether an app is install
In getLine1NumberForDisplay of PhoneInterfaceManager.java, there is apossible way to determine whether an app is install
In LabCup before <v2_next_18022, it is possible to use the save API to perform unauthorized actions for users without ac
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state manageme
Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arb
Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in in
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started