Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained
A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the fi
The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, rel
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulne
The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access
Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions w
Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allo
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with cate
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vu
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a
Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuth
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consis
Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership che
Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/
phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing atta
phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elas
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id}
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This a
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not ass
Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/ove
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of da
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, a
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnera
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all ve
The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a
The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. T
Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read a
Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging
Missing authorization in Payments in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker levera
Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t
Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t
Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin
Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r
Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t
Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started