Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 23/188
6.5
CVE-2026-34892

Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.

6.5
CVE-2026-39515

Subscriber Broken Access Control in Motors < 1.4.107 versions.

6.5
CVE-2026-39525

Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.

6.5
CVE-2026-39584

Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.

6.5
CVE-2026-40743

Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.

6.5
CVE-2026-40773

Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.

6.5
CVE-2026-40782

Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.

6.5
CVE-2026-40793

Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.

6.5
CVE-2026-40794

Subscriber Broken Access Control in myCred <= 3.0.3 versions.

6.5
CVE-2026-40795

Subscriber Broken Access Control in Amelia <= 2.2 versions.

6.5
CVE-2026-42640

Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.

6.5
CVE-2026-42659

Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.

6.5
CVE-2026-48887

Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.

6.5
CVE-2026-49775

Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

6.5
CVE-2026-2381

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a

6.5
CVE-2026-40809

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro

6.5
CVE-2026-54190

Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.

6.5
CVE-2026-53844

OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a

6.5
CVE-2026-12105

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi

6.5
CVE-2024-37210

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security

6.5
CVE-2025-69137

Subscriber Broken Access Control in Genemy <= 1.6.6 versions.

6.5
CVE-2026-39433

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

6.5
CVE-2026-45436

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

6.5
CVE-2026-49072

Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.

6.5
CVE-2026-49205

phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC

6.5
CVE-2026-52866

An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing l

6.5
CVE-2026-12119

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization c

6.5
CVE-2026-48500

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5,

6.5
CVE-2026-56402

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails

6.5
CVE-2026-56695

OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote

6.5
CVE-2026-54019

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open

6.5
CVE-2026-57429

Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.

6.5
CVE-2026-57619

Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

6.5
CVE-2026-48941

The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to ad

6.5
CVE-2026-54027

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/imag

6.5
CVE-2026-1869

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U

6.5
CVE-2026-52701

Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

6.5
CVE-2026-57324

Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.

6.5
CVE-2026-57654

Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

6.5
CVE-2026-44734

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization v

6.5
CVE-2026-3462

The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks

6.5
CVE-2026-57334

Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

6.5
CVE-2026-57335

Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.

6.5
CVE-2026-57339

Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.

6.5
CVE-2026-57340

Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.

6.5
CVE-2026-57949

ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module

6.5
CVE-2026-58167

Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HT

6.5
CVE-2026-58176

RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (

6.5
CVE-2026-9132

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to r

6.5
CVE-2026-58448

yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticate

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started