Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla exten
Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Proper
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create syst
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate the
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability chec
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capab
Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant t
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vul
Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Bro
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an impl
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convince
The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modific
The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress
Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists i
Tanium addressed an improper input validation vulnerability in Deploy.
The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all ver
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creatio
The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword JSON-RPC
The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check
Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary sys
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to
The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i
The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacke
Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged a
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and conta
The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulne
SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directl
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there
Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup
SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2.
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9,
Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow`
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started