Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 59/188
CVE-2026-78372

RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked

CVE-2026-78380

RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim

CVE-2026-78387

RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config en

CVE-2026-17548

Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who

CVE-2026-56092

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requ

CVE-2026-77128

The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user

CVE-2026-77133

The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the prof

CVE-2026-77140

The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in

CVE-2026-77141

The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and

CVE-2026-77142

The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for c

CVE-2026-77143

The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modi

CVE-2026-77146

The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-exi

CVE-2026-55541

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified p

CVE-2026-62861

TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another work

CVE-2026-81819

Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint a

CVE-2026-65931

LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu ent

CVE-2026-68929

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, th

10.0
CVE-2025-22609

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0

10.0
CVE-2025-22612

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0

10.0
CVE-2025-26853

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

10.0
CVE-2025-46348

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed

10.0
CVE-2025-45854

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

9.9
CVE-2024-57726 KEV

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to creat

9.9
CVE-2025-22611

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0

9.9
CVE-2025-49747

Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

9.9
CVE-2025-68270

The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, Cours

9.8
CVE-2024-12822

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p

9.8
CVE-2024-13513

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure

9.8
CVE-2025-27270

Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all

9.8
CVE-2025-1307

The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the news

9.8
CVE-2025-27666

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Au

9.8
CVE-2024-12876

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo

9.8
CVE-2024-12922

The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation

9.8
CVE-2025-29926

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager

9.8
CVE-2024-9095

In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to

9.8
CVE-2025-2266

The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that

9.8
CVE-2025-31681

Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authentica

9.8
CVE-2025-31691

Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: f

9.8
CVE-2025-24181

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma

9.8
CVE-2025-24245

This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4

9.8
CVE-2025-24249

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS

9.8
CVE-2025-30461

An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in mac

9.8
CVE-2025-31182

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequ

9.8
CVE-2025-31194

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS S

9.8
CVE-2024-53591

An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.

9.8
CVE-2025-37087

A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access

9.8
CVE-2025-3604

The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,

9.8
CVE-2025-46557

XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.

9.8
CVE-2025-3746

The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions

9.8
CVE-2025-3927

Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with t

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started