FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification a
toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands,
WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5,
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vuln
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token bu
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attack
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated u
Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the T
Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versi
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optim
Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up t
Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, An
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from A
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic.
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password res
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API e
OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint tha
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (S
A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameter
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss du
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the P
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access contr
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Or
Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted s
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authent
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all pla
An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpo
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6,
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control S
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remot
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for ur
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started