Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.
Subscriber Broken Access Control in Motors < 1.4.107 versions.
Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.
Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.
Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.
Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.
Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.
Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.
Subscriber Broken Access Control in myCred <= 3.0.3 versions.
Subscriber Broken Access Control in Amelia <= 2.2 versions.
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.
Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a
Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi
Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security
Subscriber Broken Access Control in Genemy <= 1.6.6 versions.
Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.
Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.
Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC
An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing l
The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization c
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5,
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to ad
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/imag
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization v
The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module
Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HT
RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to r
yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticate
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started