Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX
Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API
A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of th
A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Ove
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoi
Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions:
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attemp
A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permissio
SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privi
ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP hand
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versi
In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of m
Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team
Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_
Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams end
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions,
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modificatio
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKno
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 1
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoin
OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArg
Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attacke
The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submiss
The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users with
An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit
In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information
In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to l
In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a
Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examp
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appoi
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could h
Tanium addressed an improper access controls vulnerability in Interact.
A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. Th
A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /w
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and
TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter r
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started