CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (2,985)
CVE-2025-45854 is a critical remote code execution vulnerability in JEHC-BPM 2.0.1 that allows attackers to execute arbitrary commands via the /server...
Jun 3, 2025This vulnerability allows any authenticated user in Coolify to attach existing private SSH keys to their own server configuration. If the attacker's s...
Jan 24, 2025This critical vulnerability in the WordPress Debug Tool plugin allows attackers to upload malicious web shell files to web servers without proper auth...
Nov 16, 2024This vulnerability allows unauthenticated attackers to read and delete arbitrary files on WordPress sites using vulnerable InPost plugins. On Windows ...
Aug 17, 2024CVE-2024-6071 is a critical remote code execution vulnerability in PTC Creo Elements/Direct License Server that allows unauthenticated attackers to ex...
Jun 27, 2024CVE-2022-0543 is a critical Lua sandbox escape vulnerability in Redis on Debian-based systems that allows remote attackers to execute arbitrary code. ...
Feb 18, 2022This vulnerability allows authenticated attackers with workflow write access in one project to create and manage sites on servers belonging to other p...
Mar 6, 2026An authenticated attacker in SAP CRM and SAP S/4HANA can exploit a flaw in the Scripting Editor's generic function module to execute arbitrary SQL sta...
Feb 10, 2026This vulnerability in Open edX Platform allows CourseLimitedStaffRole users to access and edit courses in Studio when granted organization-level permi...
Dec 16, 2025This vulnerability in Coolify allows any authenticated user to escalate privileges to any role, including owner, and remove all other team members. At...
Jan 24, 2025SimpleHelp remote support software versions 5.5.7 and earlier contain an authorization vulnerability where low-privilege technicians can create API ke...
Jan 15, 2025The ThemeGrill Demo Importer WordPress plugin versions 1.3.4 through 1.6.1 contain an authentication bypass vulnerability that allows authenticated at...
Oct 16, 2024This vulnerability in Conduit's Client-Server API allows unauthorized users to manipulate room aliases, including moving the #admins alias to a contro...
Jun 25, 2024This vulnerability in the Support Genix WordPress plugin allows attackers to upload arbitrary files without proper authorization. It affects all WordP...
Apr 18, 2024CVE-2024-31997 is a critical remote code execution vulnerability in XWiki Platform where UI extension parameters are improperly executed as Velocity c...
Apr 10, 2024This vulnerability allows remote code execution in XWiki Platform via PDF export templates. Attackers can execute arbitrary code on affected XWiki ins...
Apr 10, 2024This vulnerability in XWiki Platform allows users with edit rights to modify translations without proper authorization, bypassing script or admin righ...
Apr 10, 2024A missing authorization vulnerability in Synology Surveillance Station's webapi component allows authenticated users to perform unauthorized actions. ...
Mar 28, 2024CVE-2023-34063 is a missing access control vulnerability in VMware Aria Automation that allows authenticated malicious actors to access remote organiz...
Jan 16, 2024The Frontend File Manager WordPress plugin up to version 18.2 has an authenticated settings change vulnerability. Subscriber-level attackers can modif...
Jun 7, 2023This vulnerability allows unauthenticated users to bypass ACL (Access Control List) authorizations in HashiCorp Nomad clusters where mTLS (mutual TLS)...
Apr 5, 2023This vulnerability in RubyGems.org allowed unauthorized users to remove and replace certain gems from the package registry. It affected gems with dash...
May 5, 2022SimStudio versions below 0.5.74 have MongoDB tool endpoints that accept arbitrary connection parameters without authentication or host restrictions. T...
Mar 2, 2026This vulnerability allows remote attackers to bypass authentication on GFI Archiver installations without requiring credentials. The flaw exists in th...
Feb 20, 2026CVE-2025-70150 is a critical missing authentication vulnerability in CodeAstro Membership Management System 1.0 that allows unauthenticated attackers ...
Feb 18, 2026The YayMail WordPress plugin has a privilege escalation vulnerability that allows authenticated attackers with Shop Manager access or higher to modify...
Feb 18, 2026The WP Duplicate plugin for WordPress has a critical vulnerability that allows authenticated attackers with subscriber-level access to upload arbitrar...
Feb 6, 2026This CVE describes a Missing Authorization vulnerability in the BA Book Everything WordPress plugin that allows attackers to bypass access controls. I...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Registration & Login with Mobile Phone Number for WooCommerce WordPress plugin. It all...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the Aruba HiSpeed Cache WordPress plugin that allows attackers to access functionality not...
Jan 8, 2026CVE-2025-14360 is a missing authorization vulnerability in the Kaira Blockons WordPress plugin that allows attackers to access functionality not prope...
Jan 8, 2026This CVE describes a missing authorization vulnerability in the REHub Framework WordPress plugin that allows attackers to access functionality not pro...
Jan 8, 2026This CVE describes a Missing Authorization vulnerability in the InWave Jobs WordPress plugin that allows attackers to bypass access controls. Attacker...
Jan 6, 2026CVE-2023-54327 is an authentication bypass vulnerability in Tinycontrol LAN Controller 1.58a that allows unauthenticated attackers to change administr...
Dec 30, 2025This CVE describes a Missing Authorization vulnerability in the JayBee Twitch Player WordPress plugin (ttv-easy-embed-player) that allows attackers to...
Dec 24, 2025CVE-2023-53923 is a critical privilege escalation vulnerability in UliCMS that allows unauthenticated attackers to create administrative accounts with...
Dec 17, 2025The LazyTasks WordPress plugin has an unauthenticated privilege escalation vulnerability that allows attackers to change any user's email address via ...
Dec 12, 2025CVE-2023-53740 is an authentication bypass vulnerability in Screen SFT DAB 1.9.3 that allows attackers to change the admin password without authentica...
Dec 10, 2025This vulnerability allows unauthenticated attackers to modify critical WordPress configuration options through the Frontend Admin plugin. Attackers ca...
Dec 3, 2025This CVE describes a missing authorization vulnerability in the UsersWP WordPress plugin that allows attackers to bypass access controls. It affects a...
Nov 21, 2025The Simple User Capabilities WordPress plugin has a critical privilege escalation vulnerability that allows unauthenticated attackers to elevate any u...
Nov 4, 2025This vulnerability allows unauthenticated attackers to read arbitrary email logs stored by the Post SMTP WordPress plugin, including sensitive emails ...
Nov 1, 2025Nagios XI versions before 2024R1.1.2 have a missing authorization vulnerability when 'Allow Insecure Logins' is enabled. This allows any user to creat...
Oct 30, 2025This CVE describes a Missing Authorization vulnerability in the MSTW CSV EXPORTER WordPress plugin that allows attackers to bypass access controls and...
Oct 27, 2025This CVE describes a Missing Authorization vulnerability in the Referral Link Tracker WordPress plugin that allows attackers to bypass access controls...
Oct 27, 2025This vulnerability allows unauthenticated attackers to modify WordPress site options via the MultiLoca WooCommerce plugin, potentially enabling them t...
Sep 24, 2025This vulnerability allows unauthenticated attackers to upload arbitrary ZIP files containing malicious plugins to WordPress sites using the Goza theme...
Sep 19, 2025This CVE describes a Missing Authorization vulnerability in the WordPress Login with Phone Number plugin that allows attackers to bypass authenticatio...
Aug 31, 2025The Aikaan IoT management platform v3.25.0325-5-g2e9c59796 has a critical authentication bypass vulnerability where the sign-up API endpoint remains a...
Aug 21, 2025This vulnerability allows unauthenticated attackers to change any user's email address in the Taxi Booking Manager for Woocommerce plugin, including a...
Aug 16, 2025About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 2,985 CVEs classified as CWE-862, with 211 rated critical and 809 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free