Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV ass
NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Co
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut
Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Interna
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCre
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable,
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin
Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attac
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response acti
In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves th
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit t
Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted r
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6,
IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authentica
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers wi
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises th
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowin
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoi
Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authentic
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows a
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team membe
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to
Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in ver
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a
Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged att
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user t
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. T
The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M
This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, ma
In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due
In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.
Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that
Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and ex
A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally a
Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to ex
NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause
In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started