CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

2,998
Total CVEs
213
Critical
819
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 107
2 Sap 31
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Oracle 9

All Missing Authorization CVEs (2,998)

CVE-2024-42035
8.4

A permission control vulnerability in Huawei's App Multiplier module allows unauthorized access to sensitive functionality. This affects Huawei device...

Aug 8, 2024
CVE-2024-31813
8.4

The TOTOLINK EX200 V4.0.3c.7646_B20201211 wireless range extender lacks any authentication mechanism by default, allowing unauthenticated attackers to...

Apr 8, 2024
CVE-2025-65036
8.3

CVE-2025-65036 is a critical vulnerability in XWiki Remote Macros that allows unauthenticated attackers to execute arbitrary code via Velocity templat...

Dec 5, 2025
CVE-2025-30960
8.3

This CVE describes a Missing Authorization vulnerability in the FS Poster WordPress plugin that allows unauthorized users to perform actions intended ...

Apr 16, 2025
CVE-2025-26969
8.3

This CVE describes a Missing Authorization vulnerability in the PrivateContent WordPress plugin that allows attackers to bypass access controls. Attac...

Mar 15, 2025
CVE-2023-38385
8.3

This CVE describes a Missing Authorization vulnerability in the JupiterX Core WordPress plugin that allows attackers to exploit incorrectly configured...

Dec 13, 2024
CVE-2024-38744
8.3

This CVE describes a WordPress plugin vulnerability where attackers can bypass authorization controls to access administrative functions and inject ma...

Nov 1, 2024
CVE-2023-47771
8.3

This CVE describes a Missing Authorization vulnerability in the Essential Grid WordPress plugin by ThemePunch OHG. It allows authenticated users to pe...

Jun 19, 2024
CVE-2023-25799
8.3

CVE-2023-25799 is a missing authorization vulnerability in the Tutor LMS WordPress plugin that allows unauthorized users to access student data and pe...

Jun 11, 2024
CVE-2024-33547
8.3

This CVE describes a Missing Authorization vulnerability in the AA-Team WZone WordPress plugin, allowing unauthorized users to perform actions intende...

Jun 9, 2024
CVE-2023-31080
8.3

This CVE describes a Missing Authorization vulnerability in the Unlimited Elements For Elementor WordPress plugin. It allows attackers to perform unau...

Jun 9, 2024
CVE-2020-36730
8.3

The CMP Coming Soon & Maintenance plugin for WordPress has an authorization bypass vulnerability that allows unauthenticated attackers to read posts, ...

Jun 7, 2023
CVE-2025-67956
8.2

This CVE describes a missing authorization vulnerability in the WordPress User Registration plugin that allows attackers to bypass access controls. It...

Jan 22, 2026
CVE-2026-0656
8.2

The iPaymu Payment Gateway for WooCommerce WordPress plugin has a missing authentication vulnerability that allows unauthenticated attackers to mark o...

Jan 7, 2026
CVE-2025-65742
8.2

An unauthenticated Broken Function Level Authorization vulnerability in Newgen OmniDocs v11.0 allows attackers to bypass authentication and access pri...

Dec 15, 2025
CVE-2025-58207
8.2

This vulnerability allows attackers to bypass authorization controls in the WP Messiah Ai Image Alt Text Generator WordPress plugin, enabling unauthor...

Nov 6, 2025
CVE-2025-49910
8.2

This CVE describes a Missing Authorization vulnerability in WPGuppy Lite WordPress plugin that allows attackers to access functionality not properly c...

Oct 22, 2025
CVE-2025-7040
8.2

The Cloud SAML SSO WordPress plugin has a missing capability check that allows unauthenticated attackers to modify organization settings via POST requ...

Sep 6, 2025
CVE-2025-52817
8.2

This vulnerability allows attackers to bypass authorization controls in the Abandoned Contact Form 7 WordPress plugin, potentially accessing sensitive...

Jun 27, 2025
CVE-2025-39536
8.2

This CVE describes a Missing Authorization vulnerability in the Chimpstudio JobHunt Job Alerts WordPress plugin that allows attackers to delete arbitr...

May 23, 2025
CVE-2025-39352
8.2

This vulnerability allows attackers to delete arbitrary WordPress options without proper authorization in the Grand Restaurant WordPress theme. Any Wo...

May 19, 2025
CVE-2025-32593
8.2

This CVE describes a Missing Authorization vulnerability in the Add Product Frontend for WooCommerce WordPress plugin that allows attackers to delete ...

Apr 17, 2025
CVE-2025-31678
8.2

This CVE describes a Missing Authorization vulnerability in Drupal AI that allows attackers to access restricted functionality through forceful browsi...

Mar 31, 2025
CVE-2025-26733
8.2

This CVE describes a Missing Authorization vulnerability in the Shinetheme Traveler WordPress theme that allows unauthorized users to perform actions ...

Mar 27, 2025
CVE-2025-25167
8.2

This CVE describes a missing authorization vulnerability in the BookPress WordPress plugin that allows attackers to bypass access controls. Attackers ...

Feb 7, 2025
CVE-2025-21396
8.2

This vulnerability allows unauthorized attackers to elevate privileges in Microsoft Account systems over a network. Attackers can gain higher-level ac...

Jan 29, 2025
CVE-2025-23477
8.2

This CVE describes a missing authorization vulnerability in the Realty Workstation WordPress plugin that allows attackers to access functionality not ...

Jan 21, 2025
CVE-2023-51355
8.2

This vulnerability allows attackers to bypass authorization controls in MultiVendorX WC Marketplace WordPress plugin, potentially accessing or modifyi...

Dec 9, 2024
CVE-2023-49817
8.2

This CVE describes a missing authorization vulnerability in the Flexible Woocommerce Checkout Field Editor WordPress plugin that allows attackers to b...

Dec 9, 2024
CVE-2023-48286
8.2

This CVE describes a Missing Authorization vulnerability in the Stripe Payments WordPress plugin that allows attackers to bypass access controls. It a...

Dec 9, 2024
CVE-2024-8114
8.2

This vulnerability allows attackers with access to a victim's Personal Access Token (PAT) to escalate privileges in GitLab instances. It affects all G...

Nov 26, 2024
CVE-2024-37470
8.2

This vulnerability allows unauthenticated attackers to access functionality that should be restricted by proper authorization controls in the Woffice ...

Nov 1, 2024
CVE-2024-37106
8.2

CVE-2024-37106 is a missing authorization vulnerability in the WishList Member X WordPress plugin that allows unauthenticated attackers to change plug...

Nov 1, 2024
CVE-2024-37094
8.2

This CVE describes a missing authorization vulnerability in the MasterStudy LMS WordPress plugin that allows attackers to bypass access controls and p...

Nov 1, 2024
CVE-2024-37903
8.2

This CVE describes an authorization bypass vulnerability in Mastodon where attackers can craft specific activities to extend the audience of posts the...

Jul 5, 2024
CVE-2023-39998
8.2

This CVE describes a Missing Authorization vulnerability in the Betheme WordPress theme that allows unauthorized users to perform actions intended onl...

Jun 19, 2024
CVE-2023-40608
8.2

This vulnerability allows unauthenticated attackers to bypass authorization controls in the Paid Memberships Pro CCBill Gateway WordPress plugin. Atta...

Jun 19, 2024
CVE-2024-31275
8.2

This CVE describes a Missing Authorization vulnerability in the EventPrime WordPress plugin that allows attackers to manipulate booking prices without...

Jun 9, 2024
CVE-2024-2702
8.2

This CVE describes a Missing Authorization vulnerability in the Olive One Click Demo Import WordPress plugin. It allows unauthenticated attackers to i...

Mar 20, 2024
CVE-2024-22257
8.2

This vulnerability in Spring Security allows broken access control when applications directly use AuthenticatedVoter#vote with a null Authentication p...

Mar 18, 2024
CVE-2024-1072
8.2

This vulnerability allows unauthenticated attackers to modify content on WordPress sites using the SeedProd Website Builder plugin. Attackers can chan...

Feb 5, 2024
CVE-2023-1261
8.2

CVE-2023-1261 is a missing MAC layer security vulnerability in Silicon Labs Wi-SUN SDK that allows malicious nodes to route unauthorized messages thro...

Mar 21, 2023
CVE-2026-1321
8.1

This vulnerability in the WordPress Restrict Content plugin allows unauthenticated attackers to register with any membership level, including inactive...

Mar 5, 2026
CVE-2026-24524
8.1

This CVE describes a Missing Authorization vulnerability in the Tablesome WordPress plugin that allows attackers to bypass access controls and perform...

Jan 23, 2026
CVE-2026-24357
8.1

This CVE describes a missing authorization vulnerability in the WP Recipe Maker WordPress plugin that allows attackers to bypass access controls. It a...

Jan 22, 2026
CVE-2026-24353
8.1

This CVE describes a missing authorization vulnerability in the WordPress User Registration plugin that allows attackers to exploit incorrectly config...

Jan 22, 2026
CVE-2026-23517
8.1

Fleet device management software versions before 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 have broken access control that allows any authenticated u...

Jan 21, 2026
CVE-2025-11669
8.1

This vulnerability allows attackers to bypass authorization controls in ManageEngine's privileged access management products when initiating remote se...

Jan 13, 2026
CVE-2025-59022
8.1

This vulnerability allows backend users with access to the recycler module to delete arbitrary data from any database table defined in TYPO3's TCA, re...

Jan 13, 2026
CVE-2026-0506
8.1

This CVE describes a Missing Authorization Check vulnerability in SAP ABAP systems that allows authenticated attackers to misuse RFC functions to exec...

Jan 13, 2026

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 2,998 CVEs classified as CWE-862, with 213 rated critical and 819 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free