Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to r
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control S
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket
The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missin
OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to a
OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that byp
OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions
OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through brows
OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that
The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces author
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0.
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.acc
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo
The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functio
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo
Any Editor could delete any snapshot, even if they have no access to read or write them.
The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missin
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the t
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the P
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, in st
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, GET /
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing comma
Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites whic
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Contr
The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, documen
Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security
Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue aff
A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware
A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown
The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin
Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Explo
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (E
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carrie
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service account
Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Securi
Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed
Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being
Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users t
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus
OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allo
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Co
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
Subscriber Broken Access Control in Bookify <= 1.1.1 versions.
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started