RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked
RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim
RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config en
Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who
The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requ
The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user
The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the prof
The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in
The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and
The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for c
The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modi
The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-exi
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified p
TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another work
Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint a
LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu ent
FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, th
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to creat
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, Cours
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure
Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all
The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the news
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Au
The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo
The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation
XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager
In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to
The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that
Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authentica
Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: f
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma
This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS
An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in mac
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequ
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS S
An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.
A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access
The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,
XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.
The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions
Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with t
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started