Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 6/188
8.8
CVE-2026-47405

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a brok

8.8
CVE-2026-14168

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of th

8.8
CVE-2026-49258

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*

8.8
CVE-2026-50622

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoi

8.8
CVE-2026-14356

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.

8.8
CVE-2026-17070

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b

8.8
CVE-2026-18650

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MY

8.8
CVE-2026-70619

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users

8.8
CVE-2026-8761

The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This i

8.8
CVE-2026-15991

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation

8.8
CVE-2026-48169

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa

8.8
CVE-2026-72866

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s

8.8
CVE-2026-72883

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/

8.8
CVE-2026-58243

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attack

8.8
CVE-2026-59113

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

8.8
CVE-2026-15606

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i

8.8
CVE-2026-73305

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRo

8.8
CVE-2026-72824

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::gua

8.8
CVE-2026-9771

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USE

8.8
CVE-2026-75836

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce t

8.8
CVE-2026-75853

ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (S

8.8
CVE-2026-58565

Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged atta

8.8
CVE-2026-62666

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6,

8.8
CVE-2026-76647

Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in

8.8
CVE-2026-53547

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2

8.8
CVE-2026-76319

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh

8.8
CVE-2026-31936

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object informat

8.8
CVE-2026-76847

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact

8.8
CVE-2026-19892

The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to

8.8
CVE-2026-79665

Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in RequireSc

8.8
CVE-2026-80193

Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new t

8.8
CVE-2026-80348

TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods i

8.8
CVE-2026-18965

PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on th

8.8
CVE-2026-75339

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload

8.8
CVE-2026-55521

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPac

8.7
CVE-2026-33631

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the

8.6
CVE-2025-69063

Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Config

8.6
CVE-2026-30920

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback t

8.6
CVE-2026-22343

Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.

8.6
CVE-2026-49991

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject pe

8.6
CVE-2026-55638

9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/da

8.6
CVE-2026-57206

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions

8.6
CVE-2026-64814

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

8.6
CVE-2026-68586

SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints

8.6
CVE-2026-68587

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea

8.6
CVE-2026-72789

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly access

8.6
CVE-2026-72795

SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and ge

8.6
CVE-2026-72798

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymou

8.6
CVE-2026-73608

SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4

8.6
CVE-2026-72810

SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allow

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started