Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authent
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ag
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, a
A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a spe
In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events du
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, r
GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logg
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authen
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin
WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authe
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows no
Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization
Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Con
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hit
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a l
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated at
In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles c
The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions
Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Confi
Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval b
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due t
Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocomme
act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t
An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The
OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes
Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Securi
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information di
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authen
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management
Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 vers
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and i
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an a
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which c
Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Colle
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started