CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,009
Total CVEs
217
Critical
826
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 110
2 Sap 31
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Q Free 11
9 Wpdeveloper 11
10 Apache 10

All Missing Authorization CVEs (3,009)

CVE-2020-27052
7.8

CVE-2020-27052 is an Android vulnerability that allows any app to bypass permissions and start in Lock Task Mode, which restricts users to a single ap...

Dec 15, 2020
CVE-2020-27054
7.8

This vulnerability allows local attackers to perform a factory reset on Bluetooth settings without proper permission checks. It affects Android 11 dev...

Dec 15, 2020
CVE-2020-0440
7.8

This vulnerability allows local attackers to create trusted virtual displays without proper permission checks in Android's DisplayManagerService. It e...

Dec 14, 2020
CVE-2020-23740
7.8

CVE-2020-23740 is a local privilege escalation vulnerability in DriverGenius driver update software. Attackers can exploit this vulnerability to eleva...

Dec 3, 2020
CVE-2026-24322
7.7

SAP Solution Tools Plug-In (ST-PI) contains an authorization bypass vulnerability where authenticated users can access sensitive information without p...

Feb 10, 2026
CVE-2025-15068
7.7

This CVE describes a missing authorization vulnerability in Gmission Web Fax that allows attackers to abuse authentication mechanisms and falsify sess...

Dec 29, 2025
CVE-2023-25446
7.7

This CVE describes a Missing Authorization vulnerability in HappyFiles Pro WordPress plugin that allows attackers to bypass access controls. It affect...

Dec 21, 2025
CVE-2025-42952
7.7

This vulnerability in SAP Business Warehouse and SAP Plug-In Basis allows authenticated attackers to add fields to arbitrary database tables/structure...

Jul 8, 2025
CVE-2025-27428
7.7

This directory traversal vulnerability in SAP Solution Manager allows authorized attackers to read files from any connected managed system using RFC-e...

Apr 8, 2025
CVE-2024-49657
7.7

CVE-2024-49657 is a missing authorization vulnerability in the ReneeCussack 3D Work In Progress WordPress plugin that allows attackers to delete arbit...

Oct 23, 2024
CVE-2024-39592
7.7

CVE-2024-39592 is an authorization bypass vulnerability in SAP PDCE (Product Data Cloud Edition) that allows authenticated users to escalate privilege...

Jul 9, 2024
CVE-2024-32703
7.7

This CVE describes a Missing Authorization vulnerability in the ARForms WordPress plugin that allows subscribers (low-privileged users) to delete arbi...

Jun 9, 2024
CVE-2024-1438
7.7

CVE-2024-1438 is a missing authorization vulnerability in the PressFore Rolo Slider WordPress plugin that allows attackers to perform unauthorized act...

May 8, 2024
CVE-2023-51500
7.7

CVE-2023-51500 is a missing authorization vulnerability in the Uncode Core WordPress plugin that allows attackers to delete arbitrary files on affecte...

Apr 17, 2024
CVE-2023-52713
7.7

This CVE describes an improper permission control vulnerability in the window management module of Huawei/HarmonyOS devices. It allows attackers to by...

Apr 7, 2024
CVE-2024-29228
7.7

This vulnerability allows remote authenticated users to access sensitive information through the GetStmUrlPath webapi component in Synology Surveillan...

Mar 28, 2024
CVE-2023-43700
7.7

CVE-2023-43700 is a missing authorization vulnerability in SICK APU's RDT400 component that allows unauthenticated remote attackers to modify data via...

Oct 9, 2023
CVE-2023-3442
7.7

This CVE describes a missing authorization vulnerability in the Jenkins ServiceNow DevOps plugin versions before 1.38.1. Attackers could exploit this ...

Jul 26, 2023
CVE-2021-21326
7.7

This vulnerability in GLPI allows authenticated users to create tickets on behalf of other users via the self-service interface, even when delegatee s...

Mar 8, 2021
CVE-2025-53217
7.6

This CVE describes a missing authorization vulnerability in the AIO WP Builder WordPress plugin that allows attackers to bypass access controls. It af...

Feb 20, 2026
CVE-2025-69311
7.6

This CVE describes a Missing Authorization vulnerability in the Broadstreet Ads WordPress plugin that allows attackers to bypass access controls. Atta...

Jan 22, 2026
CVE-2025-68057
7.6

This CVE describes a Missing Authorization vulnerability in the Hospital Doctor Directory WordPress plugin that allows attackers to bypass access cont...

Jan 22, 2026
CVE-2025-68058
7.6

This CVE describes a missing authorization vulnerability in the WordPress Institutions Directory plugin that allows attackers to bypass access control...

Jan 22, 2026
CVE-2025-68059
7.6

This CVE describes a Missing Authorization vulnerability in the Hotel Listing WordPress plugin that allows attackers to exploit incorrectly configured...

Jan 22, 2026
CVE-2025-67967
7.6

This CVE describes a missing authorization vulnerability in the Lawyer Directory WordPress plugin that allows attackers to bypass access controls. Att...

Jan 22, 2026
CVE-2025-7782
7.6

The WP JobHunt plugin for WordPress (used by JobCareer theme) has a missing capability check that allows authenticated attackers with Candidate-level ...

Dec 20, 2025
CVE-2025-58938
7.6

This CVE describes a Missing Authorization vulnerability in the ThemeAtelier IDonatePro WordPress plugin that allows attackers to bypass access contro...

Dec 18, 2025
CVE-2025-59826
7.6

In Flag Forge CTF platform version 2.1.0, non-admin users can create arbitrary challenges, allowing them to introduce malicious, incorrect, or mislead...

Sep 23, 2025
CVE-2025-53230
7.6

This CVE describes a missing authorization vulnerability in the Page Manager for Elementor WordPress plugin that allows attackers to bypass access con...

Aug 28, 2025
CVE-2025-53959
7.6

This vulnerability allows attackers to spoof emails through an administrative API in JetBrains YouTrack. Attackers could send emails appearing to come...

Jul 15, 2025
CVE-2025-27461
7.6

This vulnerability allows automatic login to the EPC2 Windows user account without password authentication during device startup. It affects industria...

Jul 3, 2025
CVE-2025-32308
7.6

A missing authorization vulnerability in the Team Builder WordPress plugin allows attackers to bypass access controls and perform unauthorized actions...

Jun 9, 2025
CVE-2025-31415
7.6

This CVE describes a Missing Authorization vulnerability in the YayCommerce YayExtra WordPress plugin that allows attackers to bypass access controls....

Apr 1, 2025
CVE-2024-55073
7.6

A Broken Object Level Authorization vulnerability in Mealie v2.2.0 allows authenticated users to modify their own profile to escalate privileges or ch...

Mar 27, 2025
CVE-2025-22280
7.6

This CVE describes a Missing Authorization vulnerability in the revmakx DefendWP Firewall WordPress plugin that allows attackers to exploit incorrectl...

Feb 27, 2025
CVE-2023-35037
7.6

CVE-2023-35037 is a missing authorization vulnerability in the Surfer WordPress plugin that allows attackers to bypass access controls and potentially...

Dec 13, 2024
CVE-2023-38393
7.6

This CVE describes a Missing Authorization vulnerability in the Ninja Forms WordPress plugin that allows subscribers to perform unauthorized actions. ...

Jun 19, 2024
CVE-2023-47770
7.6

This CVE describes a Missing Authorization vulnerability in the Betheme WordPress theme that allows contributors to perform actions they shouldn't hav...

Jun 19, 2024
CVE-2023-45658
7.6

This CVE describes a Missing Authorization vulnerability in the POSIMYTH Nexter WordPress theme. It allows attackers to bypass access controls and per...

Jun 19, 2024
CVE-2024-31270
7.6

This CVE describes a Missing Authorization vulnerability in the ARForms Form Builder WordPress plugin. It allows attackers to bypass access controls a...

May 8, 2024
CVE-2024-32810
7.6

This CVE describes a Missing Authorization vulnerability in the ShortPixel Critical CSS WordPress plugin. It allows attackers to perform actions witho...

May 3, 2024
CVE-2026-1916
7.5

The WPGSI: Spreadsheet Integration plugin for WordPress has critical REST API endpoints that lack proper authentication and authorization checks. Unau...

Feb 25, 2026
CVE-2025-69393
7.5

This CVE describes a missing authorization vulnerability in the Jthemes Exzo WordPress theme that allows attackers to bypass access controls. It affec...

Feb 20, 2026
CVE-2025-69303
7.5

This CVE describes a missing authorization vulnerability in the ModelTheme Framework WordPress plugin that allows attackers to bypass access controls....

Feb 20, 2026
CVE-2025-69298
7.5

This CVE describes a missing authorization vulnerability in the GhostPool Gauge WordPress theme that allows attackers to bypass access controls. The v...

Feb 20, 2026
CVE-2025-68048
7.5

This CVE describes a Missing Authorization vulnerability in the NextMove Lite WordPress plugin that allows attackers to bypass access controls. The vu...

Feb 20, 2026
CVE-2025-67994
7.5

This CVE describes a Missing Authorization vulnerability in the YayCommerce YayCurrency WordPress plugin that allows attackers to delete arbitrary con...

Feb 20, 2026
CVE-2025-11754
7.5

The GDPR Cookie Consent WordPress plugin has an unauthenticated REST API vulnerability that allows attackers to retrieve sensitive plugin settings wit...

Feb 19, 2026
CVE-2026-0692
7.5

This vulnerability allows unauthenticated attackers to spoof BlueSnap IP addresses and send forged payment notifications to WordPress sites using the ...

Feb 14, 2026
CVE-2026-0490
7.5

CVE-2026-0490 is an authentication bypass vulnerability in SAP BusinessObjects BI Platform that allows unauthenticated attackers to send crafted netwo...

Feb 10, 2026

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,009 CVEs classified as CWE-862, with 217 rated critical and 826 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free