Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in Serv
Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update
Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operat
The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and in
OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with r
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated
OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with cha
The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and includi
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 t
OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execu
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node
Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role)
OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch
The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the w
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Requi
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjac
Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. Th
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/envi
Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress
Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRU
STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attacker
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or
The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to,
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent
Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to
The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and
The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all ver
Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API ha
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthe
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass
Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage
OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated
DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Ar
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reac
OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature tha
grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started