Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
Missing Authorization vulnerability in vertim Schedula schedula-smart-appointment-booking allows Exploiting Incorrectly
Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Acce
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform un
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/n
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conver
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints fa
Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters usi
Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalI
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
Cross-repository issue/comment attachment re-linking can expose private attachment content
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sens
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat
Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive infor
The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl
The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the s
Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges cou
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that r
Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that
SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information d
SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass p
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint
SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoi
SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing
SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoint
SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeI
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter tha
SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api
SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anony
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endp
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that ret
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoin
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control m
Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption heade
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user w
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS
OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows aut
In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing per
Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Contro
In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started