Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 53/188
4.3
CVE-2026-65530

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

4.3
CVE-2026-65537

Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.

4.3
CVE-2026-16587

The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in

4.3
CVE-2026-66750

Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to dow

4.3
CVE-2026-17166

The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress

4.3
CVE-2026-5626

The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec

4.3
CVE-2026-4672

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 1

4.3
CVE-2026-67529

OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /ap

4.3
CVE-2026-10782

The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin

4.3
CVE-2026-67344

ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYP

4.3
CVE-2026-16042

The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin

4.3
CVE-2026-16289

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending me

4.3
CVE-2026-67616

Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoi

4.3
CVE-2026-16035

The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP

4.3
CVE-2026-16056

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler

4.3
CVE-2026-16546

The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA

4.3
CVE-2026-70484

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac

4.3
CVE-2026-18819

A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul

4.3
CVE-2026-7105

The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on

4.3
CVE-2026-70433

Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission t

4.3
CVE-2026-70436

Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or p

4.3
CVE-2026-70438

A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overal

4.3
CVE-2026-70445

Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permissio

4.3
CVE-2026-70446

Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to

4.3
CVE-2026-70447

Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission

4.3
CVE-2026-70618

Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user

4.3
CVE-2025-9266

The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check

4.3
CVE-2026-15246

The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no

4.3
CVE-2026-66678

Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.

4.3
CVE-2026-18276

Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated us

4.3
CVE-2026-64664

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont

4.3
CVE-2026-16965

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a

4.3
CVE-2026-72722

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_

4.3
CVE-2026-72732

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp

4.3
CVE-2026-72906

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email

4.3
CVE-2026-72919

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7

4.3
CVE-2026-58244

SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati

4.3
CVE-2026-66772

SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer

4.3
CVE-2026-14549

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of

4.3
CVE-2026-56720

CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that

4.3
CVE-2026-19052

The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac

4.3
CVE-2026-66378

An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

4.3
CVE-2026-66379

An authenticated user may view private Puppet module metadata without repository read access.

4.3
CVE-2026-66380

An authenticated user without repository read permission may access private OCI referrer metadata under specific conditi

4.3
CVE-2026-65938

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API

4.3
CVE-2026-70547

An authenticated user without repository read permission may access package metadata under specific conditions.

4.3
CVE-2026-18244

GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2

4.3
CVE-2026-73301

Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/s

4.3
CVE-2026-4879

GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2

4.3
CVE-2026-6821

GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started