Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to ob
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authen
Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model incl
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user p
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any au
Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control Securit
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Folde
Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Explo
A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unkn
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform aut
In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
Missing Authorization vulnerability in Roxnor GetGenie getgenie allows Exploiting Incorrectly Configured Access Control
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderato
Missing Authorization vulnerability in Ronik@UnlimitedWP WPSchoolPress wpschoolpress allows Exploiting Incorrectly Confi
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Sec
Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.
Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 1
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized los
The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up
Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a
NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by othe
Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o
The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in version
A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results
The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin f
Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable
Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Co
The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized m
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of
Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl
Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configu
Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting
Missing Authorization vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Exploitin
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started