Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 25/188
6.5
CVE-2026-47411

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut

6.5
CVE-2026-60712

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

6.5
CVE-2026-16544

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are

6.5
CVE-2026-57425

Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

6.5
CVE-2026-57717

Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.

6.5
CVE-2026-57808

Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.

6.5
CVE-2026-59522

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

6.5
CVE-2026-65499

Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.

6.5
CVE-2026-47755

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi

6.5
CVE-2026-49326

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest

6.5
CVE-2026-59557

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

6.5
CVE-2026-59560

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

6.5
CVE-2026-65433

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

6.5
CVE-2026-65435

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

6.5
CVE-2026-65445

Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

6.5
CVE-2026-11867

The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term

6.5
CVE-2026-18208

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source

6.5
CVE-2026-17580

The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elem

6.5
CVE-2026-13389

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST

6.5
CVE-2026-18573

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza

6.5
CVE-2026-16057

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its

6.5
CVE-2026-66326

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

6.5
CVE-2026-63248

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an

6.5
CVE-2026-7753

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing

6.5
CVE-2026-7726

The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on

6.5
CVE-2026-7456

The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec

6.5
CVE-2026-70439

Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appr

6.5
CVE-2026-25403

Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

6.5
CVE-2026-66452

Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.

6.5
CVE-2026-48075

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

6.5
CVE-2026-64662

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont

6.5
CVE-2026-11907

The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This

6.5
CVE-2026-15359

The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow

6.5
CVE-2026-47127

Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR

6.5
CVE-2026-16992

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it

6.5
CVE-2026-18037

The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it

6.5
CVE-2026-18603

The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or

6.5
CVE-2026-19345

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up

6.5
CVE-2026-19404

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati

6.5
CVE-2026-72900

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

6.5
CVE-2026-14548

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of

6.5
CVE-2026-40375

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-62915

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net

6.5
CVE-2026-65806

Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-18704

An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor

6.5
CVE-2026-69115

OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o

6.5
CVE-2026-18652

Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within

6.5
CVE-2026-47226

Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload

6.5
CVE-2026-47233

Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `

6.5
CVE-2026-68754

A repository publisher without delete permission may modify protected package content under specific conditions.

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started