The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of
The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization byp
The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modif
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload p
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /a
The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve
The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. T
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_
The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to,
The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. Th
The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cac
The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missi
The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized acc
The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl
The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi
The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas
Missing Authorization vulnerability in ThemeMove EduMall edumall allows Exploiting Incorrectly Configured Access Control
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels per
SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user c
SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user
The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and
The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin
The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGrou
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/sr
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b
A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file w
A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAu
The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in
In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
Contributor Broken Access Control in uListing <= 2.2.0 versions.
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started