CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

2,998
Total CVEs
213
Critical
819
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 107
2 Sap 31
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Oracle 9

All Missing Authorization CVEs (2,998)

CVE-2025-26368
8.1

A missing authorization vulnerability in Q-Free MaxTime allows authenticated low-privileged users to delete user groups via crafted HTTP requests. Thi...

Feb 12, 2025
CVE-2024-13656
8.1

This vulnerability in the Click Mag WordPress theme allows authenticated attackers with subscriber-level access or higher to delete arbitrary WordPres...

Feb 12, 2025
CVE-2024-13800
8.1

The ConvertPlus WordPress plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to modify c...

Feb 12, 2025
CVE-2024-13654
8.1

This vulnerability in the ZoxPress WordPress theme allows authenticated users with Subscriber-level access or higher to delete arbitrary WordPress opt...

Feb 12, 2025
CVE-2024-13767
8.1

The Live2DWebCanvas WordPress plugin has an arbitrary file deletion vulnerability that allows authenticated attackers with Subscriber-level access or ...

Jan 31, 2025
CVE-2024-46450
8.1

This vulnerability allows attackers to bypass authentication on Tenda AC1200 routers by sending specially crafted web requests. Attackers could gain u...

Jan 16, 2025
CVE-2024-11848
8.1

The NitroPack WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or higher to mod...

Jan 15, 2025
CVE-2023-41130
8.1

This CVE describes a missing authorization vulnerability in the Premmerce User Roles WordPress plugin that allows attackers to exploit incorrectly con...

Dec 13, 2024
CVE-2024-10783
8.1

This vulnerability allows unauthenticated attackers to gain administrator access on WordPress sites running MainWP Child plugin versions up to 5.2 whe...

Dec 13, 2024
CVE-2023-49856
8.1

CVE-2023-49856 is a missing authorization vulnerability in RedNao Smart Forms WordPress plugin that allows authenticated users to change arbitrary opt...

Dec 9, 2024
CVE-2024-42453
8.1

CVE-2024-42453 is a privilege escalation vulnerability in Veeam Backup & Replication that allows low-privileged users to perform unauthorized actions ...

Dec 4, 2024
CVE-2024-11104
8.1

This vulnerability in Sky Addons for Elementor WordPress plugin allows authenticated attackers with subscriber-level access or higher to modify arbitr...

Nov 22, 2024
CVE-2024-11601
8.1

This CSRF vulnerability in Sky Addons for Elementor allows unauthenticated attackers to modify WordPress site options via forged requests that trick a...

Nov 22, 2024
CVE-2024-21250
8.1

This vulnerability in Oracle Process Manufacturing Product Development allows authenticated attackers with low privileges to perform unauthorized data...

Oct 15, 2024
CVE-2024-21252
8.1

This vulnerability in Oracle Product Hub allows authenticated attackers with low privileges to manipulate critical data or access sensitive informatio...

Oct 15, 2024
CVE-2024-8548
8.1

This vulnerability in the KB Support WordPress plugin allows authenticated attackers with Subscriber-level access or higher to perform unauthorized ad...

Oct 1, 2024
CVE-2023-37870
8.1

This CVE describes a missing authorization vulnerability in the WooCommerce Warranty Requests WordPress plugin. It allows attackers to bypass access c...

Jun 19, 2024
CVE-2024-31098
8.1

This CVE describes a Missing Authorization vulnerability in the WordPress plugin 'New Order Notification for Woocommerce' by Mr.Ebabi. It allows unaut...

Jun 9, 2024
CVE-2023-6966
8.1

The Moneytizer WordPress plugin has a missing capability check vulnerability that allows authenticated users with subscriber-level access or higher to...

Jun 6, 2024
CVE-2024-1862
8.1

This vulnerability in the WooCommerce Add to Cart Custom Redirect plugin allows authenticated attackers with contributor-level access or higher to mod...

Mar 13, 2024
CVE-2023-48222
8.1

This vulnerability allows authenticated users in Rundeck to bypass authorization checks and access two specific URLs, enabling them to view or delete ...

Nov 16, 2023
CVE-2023-4606
8.1

This vulnerability allows authenticated users with read-only permissions on Lenovo ThinkSystem servers to change other users' passwords through a craf...

Oct 25, 2023
CVE-2023-37910
8.1

This vulnerability in XWiki Platform allows attackers with edit access to any document (including default-editable user profiles) to move any attachme...

Oct 25, 2023
CVE-2023-39438
8.1

CVE-2023-39438 is an authorization bypass vulnerability in CLA-assistant that allows any authenticated user to read, update, or delete CLA (Contributo...

Aug 15, 2023
CVE-2021-4383
8.1

The WP Quick FrontEnd Editor plugin for WordPress has a missing capability check vulnerability that allows low-privileged authenticated users (like su...

Jun 7, 2023
CVE-2023-25552
8.1

This vulnerability in StruxureWare Data Center Expert allows attackers to bypass authorization controls and perform unauthorized actions like viewing,...

Apr 18, 2023
CVE-2022-45636
8.1

This vulnerability allows attackers to unlock MEGAFEIS and BOFEI DBD+ smart locks without authorization by sending arbitrary API requests to the mobil...

Mar 21, 2023
CVE-2022-1903
8.1

The ARMember WordPress plugin before version 3.4.8 contains an authentication bypass vulnerability that allows unauthenticated attackers to reset pass...

Jun 27, 2022
CVE-2021-37764
8.1

This vulnerability allows attackers to delete arbitrary files on XOS-Shop systems by manipulating the current_manufacturer_image parameter in the manu...

Jun 16, 2022
CVE-2022-25342
8.1

This CVE describes a broken access control vulnerability in Olivetti d-COLOR MF3555 multifunction printers. Attackers can bypass authentication and ac...

Apr 20, 2022
CVE-2021-41112
8.1

This vulnerability allows authenticated Rundeck users to modify or delete system or project calendars without proper authorization. This could cause s...

Feb 28, 2022
CVE-2022-21660
8.1

CVE-2022-21660 is an authentication bypass vulnerability in gin-vue-admin where low-privilege users can modify higher-privilege user accounts due to m...

Feb 9, 2022
CVE-2021-40501
8.1

CVE-2021-40501 is an authorization bypass vulnerability in SAP ABAP Platform Kernel that allows authenticated business users to escalate privileges an...

Nov 10, 2021
CVE-2021-40884
8.1

Projectsend r1295 has an authorization bypass vulnerability that allows users with uploader role to download and edit all files in the application. Th...

Oct 11, 2021
CVE-2021-40378
8.1

This vulnerability allows unauthenticated attackers to delete all data from affected Compro IP camera devices by accessing a specific CGI script. It a...

Sep 1, 2021
CVE-2020-11511
8.1

This vulnerability in the LearnPress WordPress plugin allows remote attackers to escalate any user's privileges to 'LP Instructor' role via the 'accep...

Jul 30, 2021
CVE-2021-27900
8.1

This vulnerability allows view-only users in Proofpoint Insider Threat Management Server to bypass authorization checks and perform administrative act...

Apr 6, 2021
CVE-2020-13422
8.1

OpenIAM versions before 4.2.0.3 have an authorization bypass vulnerability in the administrative REST API endpoints. Attackers can perform administrat...

Apr 6, 2021
CVE-2026-26268
8.0

This CVE describes a sandbox escape vulnerability in Cursor code editor versions prior to 2.5. A malicious AI agent could write to improperly protecte...

Feb 13, 2026
CVE-2023-43488
7.9

This vulnerability allows low-privileged applications to modify critical system properties to enable ADB over network, potentially granting attackers ...

Oct 25, 2023
CVE-2026-20626
7.8

This vulnerability allows a malicious application to gain root privileges on affected Apple devices. It affects macOS, iOS, iPadOS, and visionOS syste...

Feb 11, 2026
CVE-2025-48599
7.8

This vulnerability allows local attackers to bypass device configuration restrictions in Android's WiFi settings due to missing permission checks. It ...

Dec 8, 2025
CVE-2025-48575
7.8

This vulnerability allows local attackers to install arbitrary certificates on Android devices without proper permissions, enabling local privilege es...

Dec 8, 2025
CVE-2025-43316
7.8

A permissions vulnerability in visionOS allows malicious applications to escalate privileges and gain root access. This affects visionOS devices runni...

Sep 15, 2025
CVE-2025-43286
7.8

A sandbox escape vulnerability in macOS allows malicious applications to bypass security restrictions and access system resources or other application...

Sep 15, 2025
CVE-2025-49459
7.8

This vulnerability allows authenticated users on Windows ARM systems to escalate privileges through Zoom Workplace's installer due to missing authoriz...

Sep 9, 2025
CVE-2025-22414
7.8

This vulnerability allows attackers to bypass Factory Reset Protection (FRP) on Android Wear devices without requiring user interaction or additional ...

Sep 4, 2025
CVE-2025-26450
7.8

This vulnerability allows untrusted Android apps to inject keyboard and touch events into the default Input Method Editor (IME) without proper permiss...

Sep 4, 2025
CVE-2025-41698
7.8

A local privilege escalation vulnerability allows low-privileged users to interact with a service that should be restricted. This affects systems runn...

Aug 5, 2025
CVE-2025-52954
7.8

A Missing Authorization vulnerability in Juniper Networks Junos OS Evolved allows local low-privileged users to gain root privileges by sending packet...

Jul 11, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 2,998 CVEs classified as CWE-862, with 213 rated critical and 819 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free