An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to
The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the W
The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Pri
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS expo
The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the
The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads
The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_inf
The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o
The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin
The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio
A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUS
The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Se
The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed d
A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attacker
Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads du
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi
Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.
Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper acc
Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option i
The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to
The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability chec
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress
The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to,
UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escal
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password
The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable
UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrati
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers t
RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalatio
A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based atta
JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution pa
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deplo
PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubN
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and i
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to
Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academ
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an atta
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024
The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in version
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started