The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data th
The Eco Nature - Environment & Ecology WordPress Theme theme for WordPress is vulnerable to unauthorized modification of
In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by
An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the fir
The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modificati
The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of
The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data t
Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to st
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or al
Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting
The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F
The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypas
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 a
In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-p
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missin
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capa
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo
A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series fi
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wi
Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.
Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing A
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference
The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification o
Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwis
In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profil
A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS
A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.
In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permi
In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motio
In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. T
In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permiss
Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authentic
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26, visionOS 26. A ma
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26
In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass
In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to
Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using
Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization c
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database ta
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of dat
Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification th
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started