CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,009)
CVE-2020-27052 is an Android vulnerability that allows any app to bypass permissions and start in Lock Task Mode, which restricts users to a single ap...
Dec 15, 2020This vulnerability allows local attackers to perform a factory reset on Bluetooth settings without proper permission checks. It affects Android 11 dev...
Dec 15, 2020This vulnerability allows local attackers to create trusted virtual displays without proper permission checks in Android's DisplayManagerService. It e...
Dec 14, 2020CVE-2020-23740 is a local privilege escalation vulnerability in DriverGenius driver update software. Attackers can exploit this vulnerability to eleva...
Dec 3, 2020SAP Solution Tools Plug-In (ST-PI) contains an authorization bypass vulnerability where authenticated users can access sensitive information without p...
Feb 10, 2026This CVE describes a missing authorization vulnerability in Gmission Web Fax that allows attackers to abuse authentication mechanisms and falsify sess...
Dec 29, 2025This CVE describes a Missing Authorization vulnerability in HappyFiles Pro WordPress plugin that allows attackers to bypass access controls. It affect...
Dec 21, 2025This vulnerability in SAP Business Warehouse and SAP Plug-In Basis allows authenticated attackers to add fields to arbitrary database tables/structure...
Jul 8, 2025This directory traversal vulnerability in SAP Solution Manager allows authorized attackers to read files from any connected managed system using RFC-e...
Apr 8, 2025CVE-2024-49657 is a missing authorization vulnerability in the ReneeCussack 3D Work In Progress WordPress plugin that allows attackers to delete arbit...
Oct 23, 2024CVE-2024-39592 is an authorization bypass vulnerability in SAP PDCE (Product Data Cloud Edition) that allows authenticated users to escalate privilege...
Jul 9, 2024This CVE describes a Missing Authorization vulnerability in the ARForms WordPress plugin that allows subscribers (low-privileged users) to delete arbi...
Jun 9, 2024CVE-2024-1438 is a missing authorization vulnerability in the PressFore Rolo Slider WordPress plugin that allows attackers to perform unauthorized act...
May 8, 2024CVE-2023-51500 is a missing authorization vulnerability in the Uncode Core WordPress plugin that allows attackers to delete arbitrary files on affecte...
Apr 17, 2024This CVE describes an improper permission control vulnerability in the window management module of Huawei/HarmonyOS devices. It allows attackers to by...
Apr 7, 2024This vulnerability allows remote authenticated users to access sensitive information through the GetStmUrlPath webapi component in Synology Surveillan...
Mar 28, 2024CVE-2023-43700 is a missing authorization vulnerability in SICK APU's RDT400 component that allows unauthenticated remote attackers to modify data via...
Oct 9, 2023This CVE describes a missing authorization vulnerability in the Jenkins ServiceNow DevOps plugin versions before 1.38.1. Attackers could exploit this ...
Jul 26, 2023This vulnerability in GLPI allows authenticated users to create tickets on behalf of other users via the self-service interface, even when delegatee s...
Mar 8, 2021This CVE describes a missing authorization vulnerability in the AIO WP Builder WordPress plugin that allows attackers to bypass access controls. It af...
Feb 20, 2026This CVE describes a Missing Authorization vulnerability in the Broadstreet Ads WordPress plugin that allows attackers to bypass access controls. Atta...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Hospital Doctor Directory WordPress plugin that allows attackers to bypass access cont...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the WordPress Institutions Directory plugin that allows attackers to bypass access control...
Jan 22, 2026This CVE describes a Missing Authorization vulnerability in the Hotel Listing WordPress plugin that allows attackers to exploit incorrectly configured...
Jan 22, 2026This CVE describes a missing authorization vulnerability in the Lawyer Directory WordPress plugin that allows attackers to bypass access controls. Att...
Jan 22, 2026The WP JobHunt plugin for WordPress (used by JobCareer theme) has a missing capability check that allows authenticated attackers with Candidate-level ...
Dec 20, 2025This CVE describes a Missing Authorization vulnerability in the ThemeAtelier IDonatePro WordPress plugin that allows attackers to bypass access contro...
Dec 18, 2025In Flag Forge CTF platform version 2.1.0, non-admin users can create arbitrary challenges, allowing them to introduce malicious, incorrect, or mislead...
Sep 23, 2025This CVE describes a missing authorization vulnerability in the Page Manager for Elementor WordPress plugin that allows attackers to bypass access con...
Aug 28, 2025This vulnerability allows attackers to spoof emails through an administrative API in JetBrains YouTrack. Attackers could send emails appearing to come...
Jul 15, 2025This vulnerability allows automatic login to the EPC2 Windows user account without password authentication during device startup. It affects industria...
Jul 3, 2025A missing authorization vulnerability in the Team Builder WordPress plugin allows attackers to bypass access controls and perform unauthorized actions...
Jun 9, 2025This CVE describes a Missing Authorization vulnerability in the YayCommerce YayExtra WordPress plugin that allows attackers to bypass access controls....
Apr 1, 2025A Broken Object Level Authorization vulnerability in Mealie v2.2.0 allows authenticated users to modify their own profile to escalate privileges or ch...
Mar 27, 2025This CVE describes a Missing Authorization vulnerability in the revmakx DefendWP Firewall WordPress plugin that allows attackers to exploit incorrectl...
Feb 27, 2025CVE-2023-35037 is a missing authorization vulnerability in the Surfer WordPress plugin that allows attackers to bypass access controls and potentially...
Dec 13, 2024This CVE describes a Missing Authorization vulnerability in the Ninja Forms WordPress plugin that allows subscribers to perform unauthorized actions. ...
Jun 19, 2024This CVE describes a Missing Authorization vulnerability in the Betheme WordPress theme that allows contributors to perform actions they shouldn't hav...
Jun 19, 2024This CVE describes a Missing Authorization vulnerability in the POSIMYTH Nexter WordPress theme. It allows attackers to bypass access controls and per...
Jun 19, 2024This CVE describes a Missing Authorization vulnerability in the ARForms Form Builder WordPress plugin. It allows attackers to bypass access controls a...
May 8, 2024This CVE describes a Missing Authorization vulnerability in the ShortPixel Critical CSS WordPress plugin. It allows attackers to perform actions witho...
May 3, 2024The WPGSI: Spreadsheet Integration plugin for WordPress has critical REST API endpoints that lack proper authentication and authorization checks. Unau...
Feb 25, 2026This CVE describes a missing authorization vulnerability in the Jthemes Exzo WordPress theme that allows attackers to bypass access controls. It affec...
Feb 20, 2026This CVE describes a missing authorization vulnerability in the ModelTheme Framework WordPress plugin that allows attackers to bypass access controls....
Feb 20, 2026This CVE describes a missing authorization vulnerability in the GhostPool Gauge WordPress theme that allows attackers to bypass access controls. The v...
Feb 20, 2026This CVE describes a Missing Authorization vulnerability in the NextMove Lite WordPress plugin that allows attackers to bypass access controls. The vu...
Feb 20, 2026This CVE describes a Missing Authorization vulnerability in the YayCommerce YayCurrency WordPress plugin that allows attackers to delete arbitrary con...
Feb 20, 2026The GDPR Cookie Consent WordPress plugin has an unauthenticated REST API vulnerability that allows attackers to retrieve sensitive plugin settings wit...
Feb 19, 2026This vulnerability allows unauthenticated attackers to spoof BlueSnap IP addresses and send forged payment notifications to WordPress sites using the ...
Feb 14, 2026CVE-2026-0490 is an authentication bypass vulnerability in SAP BusinessObjects BI Platform that allows unauthenticated attackers to send crafted netwo...
Feb 10, 2026About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,009 CVEs classified as CWE-862, with 217 rated critical and 826 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free