Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 74/188
6.4
CVE-2025-12583

The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab

6.4
CVE-2025-11003

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz

6.4
CVE-2025-13866

The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missin

6.3
CVE-2024-56266

Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-

6.3
CVE-2025-0067

Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with

6.3
CVE-2024-13361

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability che

6.3
CVE-2025-0939

The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on

6.3
CVE-2025-1214

A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file

6.3
CVE-2025-22698

Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrect

6.3
CVE-2025-22702

Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Acces

6.3
CVE-2025-23440

Missing Authorization vulnerability in radicaldesigns radSLIDE radslide allows Exploiting Incorrectly Configured Access

6.3
CVE-2025-1325

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode executi

6.3
CVE-2025-31841

Missing Authorization vulnerability in Frank P. Walentynowicz FPW Category Thumbnails fpw-category-thumbnails allows Exp

6.3
CVE-2025-43007

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a

6.3
CVE-2025-43009

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing a

6.3
CVE-2025-5692

The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capabili

6.3
CVE-2025-47565

Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control

6.3
CVE-2025-8807

A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects un

6.3
CVE-2025-11438

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /cust

6.3
CVE-2025-49377

Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Acc

6.3
CVE-2025-53236

Missing Authorization vulnerability in AndonDesign UDesign Core u-design-core allows Exploiting Incorrectly Configured A

6.3
CVE-2025-36361

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user

6.3
CVE-2025-2848

A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings,

6.3
CVE-2025-0836

Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management S

6.3
CVE-2025-64192

Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Secu

6.3
CVE-2025-15390

A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edi

6.2
CVE-2025-54608

Vulnerability that allows setting screen rotation direction without permission verification in the screen management mod

6.2
CVE-2025-0086

In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission c

6.2
CVE-2025-43318

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Tahoe 26. An app with root pri

6.2
CVE-2025-15066

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Authorization vulnerability in I

6.1
CVE-2025-21527

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC). Support

6.1
CVE-2025-8887

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unautho

5.9
CVE-2025-22385

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B

5.9
CVE-2025-11380

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u

5.8
CVE-2025-22720

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme

5.8
CVE-2025-24607

Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configu

5.8
CVE-2025-31876

Missing Authorization vulnerability in gunnarpayday Payday payday allows Exploiting Incorrectly Configured Access Contro

5.8
CVE-2025-39580

Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by

5.8
CVE-2025-43008

Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclos

5.8
CVE-2025-2246

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1

5.8
CVE-2025-54734

Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Contro

5.8
CVE-2025-62642

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" sign

5.8
CVE-2025-54743

Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly

5.7
CVE-2025-25244

SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorizat

5.6
CVE-2025-1055

A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege use

5.6
CVE-2025-13813

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the f

5.5
CVE-2018-9406

In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead

5.5
CVE-2025-22607

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0

5.5
CVE-2025-24096

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app m

5.5
CVE-2025-24108

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3. An app ma

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started