In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted permission due to a
MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it
eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid gue
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resour
eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 1
SiteVision 4 has Incorrect Access Control.
EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticat
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is e
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal com
An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox e
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execut
In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission ch
In isPackageDeviceAdminOnAnyUser of PackageManagerService.java, there is a possible permissions bypass due to a missing
In GetPermittedAccessibilityServicesForUser of DevicePolicyManagerService.java, there is a possible permissions bypass d
In isSeparateProfileChallengeAllowed of DevicePolicyManagerService.java, there is a possible permissions bypass due to a
In areNotificationsEnabledForPackage of NotificationManagerService.java, there is a possible permissions bypass due to a
kernel/sys/syscall.c in ToaruOS through 1.10.9 has incorrect access control in sys_sysfunc case 9 for TOARU_SYS_FUNC_SET
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSave
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emul
In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could l
In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check.
In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before
EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attac
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `r
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `r
The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in t
An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Char
A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read perm
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remot
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php. A remote unauthenticated
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthentica
doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php. A remote unauthenticated
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to
Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attac
MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password info
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory struc
eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorizati
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participa
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started