Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 54/188
4.3
CVE-2026-6470

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and

4.3
CVE-2026-50105

RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

4.3
CVE-2026-72671

A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained

4.3
CVE-2026-19786

A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the fi

4.3
CVE-2026-18807

The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, rel

4.3
CVE-2026-13167

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulne

4.3
CVE-2026-16779

The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin

4.3
CVE-2026-15345

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization

4.3
CVE-2026-18347

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa

4.3
CVE-2026-16047

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access

4.3
CVE-2026-16049

Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions w

4.3
CVE-2026-55704

Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allo

4.3
CVE-2026-59829

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with cate

4.3
CVE-2026-75046

In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

4.3
CVE-2026-75151

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vu

4.3
CVE-2026-75832

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a

4.3
CVE-2026-75835

Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuth

4.3
CVE-2026-74003

Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.

4.3
CVE-2026-74006

Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

4.3
CVE-2026-45124

MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consis

4.3
CVE-2026-71322

Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership che

4.3
CVE-2026-76032

Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/

4.3
CVE-2026-76209

phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endpoints, allowing atta

4.3
CVE-2026-76211

phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elas

4.3
CVE-2026-55703

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id}

4.3
CVE-2026-76360

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to

4.3
CVE-2026-76398

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the

4.3
CVE-2026-61663

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

4.3
CVE-2026-77391

A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This a

4.3
CVE-2026-33047

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not ass

4.3
CVE-2026-53487

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/ove

4.3
CVE-2026-76057

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP

4.3
CVE-2026-76074

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP

4.3
CVE-2026-4244

The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability

4.3
CVE-2026-5093

The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of da

4.3
CVE-2026-14853

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, a

4.3
CVE-2026-19801

The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnera

4.3
CVE-2026-75930

The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all ve

4.3
CVE-2026-78467

The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a

4.3
CVE-2026-75908

The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. T

4.3
CVE-2026-79669

Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read a

4.3
CVE-2026-79041

Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging

4.3
CVE-2026-79042

Missing authorization in Payments in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker levera

4.3
CVE-2026-79067

Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

4.3
CVE-2026-79085

Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

4.3
CVE-2026-79110

Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin

4.3
CVE-2026-79116

Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r

4.3
CVE-2026-79184

Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t

4.3
CVE-2026-79212

Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

4.3
CVE-2026-81284

Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started