The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz
The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missin
Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-
Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability che
The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on
A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file
Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrect
Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Acces
Missing Authorization vulnerability in radicaldesigns radSLIDE radslide allows Exploiting Incorrectly Configured Access
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode executi
Missing Authorization vulnerability in Frank P. Walentynowicz FPW Category Thumbnails fpw-category-thumbnails allows Exp
SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a
SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a
The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capabili
Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control
A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects un
A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /cust
Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Acc
Missing Authorization vulnerability in AndonDesign UDesign Core u-design-core allows Exploiting Incorrectly Configured A
IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user
A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings,
Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management S
Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Secu
A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edi
Vulnerability that allows setting screen rotation direction without permission verification in the screen management mod
In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission c
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Tahoe 26. An app with root pri
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Authorization vulnerability in I
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC). Support
Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unautho
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme
Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configu
Missing Authorization vulnerability in gunnarpayday Payday payday allows Exploiting Incorrectly Configured Access Contro
Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by
Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclos
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1
Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Contro
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" sign
Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly
SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorizat
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege use
A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the f
In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app m
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3. An app ma
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started