Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 58/188
CVE-2026-46515

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call

CVE-2026-44176

Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` per

CVE-2026-45334

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature ret

CVE-2026-12715

Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an at

CVE-2026-15783

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with

CVE-2026-45704

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses i

CVE-2026-57494

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-p

CVE-2026-8593

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49,

CVE-2026-47394

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is in

CVE-2026-47657

HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in

CVE-2026-7328

Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CM

CVE-2026-59677

A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined

CVE-2026-66723

MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API.

CVE-2026-66724

MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob u

CVE-2026-15228

Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust

CVE-2026-16543

Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation pr

CVE-2026-15227

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking t

CVE-2026-69252

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/fil

CVE-2026-13229

Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning end

CVE-2026-70473

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow

CVE-2026-70475

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1

CVE-2026-13227

An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access co

CVE-2026-47765

Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints

CVE-2026-54201

Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these lo

CVE-2026-17601

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their

CVE-2026-66058

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follo

CVE-2026-72759

In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization

CVE-2025-30237

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not c

CVE-2026-73140

Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report ex

CVE-2026-73155

Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first

CVE-2026-19539

Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5

CVE-2026-73405

An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to S

CVE-2026-47718

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` s

CVE-2026-73603

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing atta

CVE-2026-73665

FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in

CVE-2026-64866

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 un

CVE-2026-67440

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVIC

CVE-2026-67443

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard autho

CVE-2026-53453

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio

CVE-2026-45273

MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler

CVE-2026-64852

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.8,

CVE-2026-55483

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission ca

CVE-2026-54741

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy blocks new private me

CVE-2026-64965

ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticat

CVE-2026-55095

OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-a

CVE-2026-53569

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_a

CVE-2026-19755

NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled c

CVE-2026-12710

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025

CVE-2026-78365

Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 all

CVE-2026-78370

RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated rem

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started