PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source
The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elem
The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing
The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on
The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appr
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont
The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This
The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow
Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR
The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it
The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it
The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or
A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati
Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor
OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o
Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within
Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload
Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `
A repository publisher without delete permission may modify protected package content under specific conditions.
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started