In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the
In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead t
Windows Logon Integration feature of F5 BIG-IP APM client prior to version 7.1.7.1 for Windows by default uses Legacy lo
While accessing SafeSwitch services, third party can manipulate a given device and perform unauthorized operation due to
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, a
The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but thi
WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject script
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all ref
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128.
By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that shoul
In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run co
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administ
A vulnerability in the network-operator user role implementation for Cisco NX-OS System Software could allow an authenti
A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated
Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed aut
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user
The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/relea
In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some v
Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x befor
Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to injec
The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions b
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x befor
In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a
In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. Th
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated atta
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in e
Electrum Technologies GmbH Electrum Bitcoin Wallet version prior to version 3.0.5 contains a Missing Authorization vulne
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on t
A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote
On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Bui
A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_au
Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modi
Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone w
The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream
The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before versi
A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a rep
In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intende
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in e
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote a
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate pe
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM)
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulti
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticate
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started