RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co
A low-privileged authenticated user may access restricted support information under specific conditions.
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check
Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Co
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on manag
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kiba
SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint tha
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other
Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/int
ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation f
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require Authorit
The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower-ranked remote moder
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10
Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and a
TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arb
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint t
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated us
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under speci
Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social
Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t
Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the
Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compro
Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system acce
Missing authorization in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social en
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce
Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started