Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 26/188
6.5
CVE-2026-73265

RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co

6.5
CVE-2026-68758

A low-privileged authenticated user may access restricted support information under specific conditions.

6.5
CVE-2026-68971

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check

6.5
CVE-2026-27999

Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.

6.5
CVE-2026-28159

Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.

6.5
CVE-2026-28181

Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.

6.5
CVE-2026-61978

Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.

6.5
CVE-2026-66454

Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.

6.5
CVE-2026-66459

Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.

6.5
CVE-2026-66464

Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.

6.5
CVE-2026-66660

Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.

6.5
CVE-2026-66693

Subscriber Broken Access Control in Motors <= 1.4.113 versions.

6.5
CVE-2026-72661

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Co

6.5
CVE-2026-72664

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on manag

6.5
CVE-2026-72681

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kiba

6.5
CVE-2026-72812

SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint tha

6.5
CVE-2026-75049

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other

6.5
CVE-2026-73424

Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/int

6.5
CVE-2026-63669

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation f

6.5
CVE-2026-69146

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.

6.5
CVE-2026-66651

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.

6.5
CVE-2026-73348

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

6.5
CVE-2026-73352

Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.

6.5
CVE-2026-73404

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

6.5
CVE-2026-71317

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require Authorit

6.5
CVE-2026-12631

The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/

6.5
CVE-2026-73363

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.

6.5
CVE-2026-54740

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower-ranked remote moder

6.5
CVE-2026-76257

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10

6.5
CVE-2025-53999

Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.

6.5
CVE-2026-66647

Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.

6.5
CVE-2026-54624

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

6.5
CVE-2026-63003

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

6.5
CVE-2026-54509

TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src

6.5
CVE-2026-34836

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and a

6.5
CVE-2026-39914

TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arb

6.5
CVE-2026-71508

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows

6.5
CVE-2026-71509

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint t

6.5
CVE-2026-27364

Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.

6.5
CVE-2026-78266

Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

6.5
CVE-2026-79666

Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated us

6.5
CVE-2026-70550

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under speci

6.5
CVE-2026-78897

Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social

6.5
CVE-2026-78967

Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

6.5
CVE-2026-78968

Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the

6.5
CVE-2026-79021

Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compro

6.5
CVE-2026-79099

Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system acce

6.5
CVE-2026-79154

Missing authorization in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social en

6.5
CVE-2026-55545

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce

6.5
CVE-2026-82273

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started