GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, whi
Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on fold
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .F
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w
Backend users were able to move records to a different page without having edit permissions on the source page. This iss
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch
Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission
Backend users with write access to the form_definition database table were able to directly create, update, or delete fo
A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform all
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any g
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can res
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in
Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple
A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerabili
A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The co
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The upda
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, th
Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o
A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud C
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3,
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theA
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff ac
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged st
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `ser
Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared us
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en
Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user ena
An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys wit
The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with role
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enab
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.acce
Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked approp
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach
Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_pag
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Co
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on
ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows a
Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/o
Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publicatio
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started