Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 42/188
5.3
CVE-2026-18437

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access

5.3
CVE-2026-11995

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress

5.3
CVE-2026-70487

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di

5.3
CVE-2026-16290

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member

5.3
CVE-2026-11983

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up

5.3
CVE-2026-32548

Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.

5.3
CVE-2026-66699

Custom role Broken Access Control in Dokan <= 5.0.10 versions.

5.3
CVE-2026-66701

Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

5.3
CVE-2026-48077

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

5.3
CVE-2026-16608

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging

5.3
CVE-2026-15237

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a RES

5.3
CVE-2026-17021

The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modif

5.3
CVE-2026-72723

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano

5.3
CVE-2026-18035

The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo

5.3
CVE-2026-66377

An unauthenticated user may access restricted repository information under specific conditions.

5.3
CVE-2026-68753

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in

5.3
CVE-2026-73349

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

5.3
CVE-2026-73353

Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.

5.3
CVE-2026-73401

Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.

5.3
CVE-2026-73403

Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.

5.3
CVE-2026-8840

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versi

5.3
CVE-2026-53960

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwis

5.3
CVE-2026-55106

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source AP

5.3
CVE-2026-65959

Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint

5.3
CVE-2026-18777

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allo

5.3
CVE-2026-18779

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allo

5.3
CVE-2026-76215

phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments an

5.3
CVE-2026-76340

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-s

5.3
CVE-2026-17153

The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi

5.3
CVE-2026-28163

Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control S

5.3
CVE-2026-16962

The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its p

5.3
CVE-2026-75027

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8

5.3
CVE-2026-78258

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.

5.3
CVE-2026-78291

Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

5.3
CVE-2026-10627

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass i

5.3
CVE-2026-17587

The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass i

5.3
CVE-2026-79044

Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker

5.3
CVE-2026-79104

Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th

5.3
CVE-2026-13172

The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in

5.3
CVE-2026-13406

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before r

5.3
CVE-2026-14550

The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through i

5.3
CVE-2026-75798

The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only f

5.3
CVE-2026-77694

The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed t

5.3
CVE-2026-77507

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

5.3
CVE-2026-81274

Subscriber Broken Access Control in Ditty <= 3.1.67 versions.

5.3
CVE-2026-81276

Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.

5.3
CVE-2026-12514

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capab

5.3
CVE-2026-77701

The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns t

5.3
CVE-2026-19430

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and th

5.2
CVE-2026-24312

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started