CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

2,993
Total CVEs
212
Critical
815
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 107
2 Sap 31
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Oracle 9

All Missing Authorization CVEs (2,993)

CVE-2018-25105
9.8

The File Manager WordPress plugin versions up to 3.0 contain an authorization bypass vulnerability that allows unauthenticated attackers to download a...

Oct 16, 2024
CVE-2024-21216
9.8

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to fully compromise the ser...

Oct 15, 2024
CVE-2024-9707
9.8

The Hunk Companion WordPress plugin has an unauthenticated REST API vulnerability that allows attackers to install and activate arbitrary plugins. Thi...

Oct 11, 2024
CVE-2024-9234
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files and install/activate arbitrary plugins on WordPress sites using the Gute...

Oct 11, 2024
CVE-2024-8289
9.8

This vulnerability in the MultiVendorX WordPress plugin allows unauthenticated attackers to perform privilege escalation and account takeover attacks....

Sep 4, 2024
CVE-2024-4259
9.8

This CVE describes a Missing Authorization vulnerability in SAMPAŞ Holding's AKOS services that allows unauthorized data collection. Attackers can ex...

Sep 3, 2024
CVE-2024-41730
9.8

This vulnerability allows unauthorized users to obtain logon tokens via a REST endpoint when Single Sign-On is enabled with Enterprise authentication ...

Aug 13, 2024
CVE-2024-6806
9.8

CVE-2024-6806 is a critical authorization bypass vulnerability in NI VeriStand Gateway that allows unauthorized actors to access project resources. Th...

Jul 22, 2024
CVE-2024-6636
9.8

The WooCommerce Social Login plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to register account...

Jul 20, 2024
CVE-2024-6328
9.8

The MStore API WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user by exp...

Jul 12, 2024
CVE-2024-4898
9.8

This vulnerability allows unauthenticated attackers to modify arbitrary WordPress site options and create administrator accounts via the InstaWP Conne...

Jun 12, 2024
CVE-2024-31244
9.8

CVE-2024-31244 is a Missing Authorization vulnerability in the Bricksforge WordPress plugin that allows unauthenticated attackers to change arbitrary ...

Jun 9, 2024
CVE-2024-36246
9.8

This CVE describes a missing authorization vulnerability in Unifier and Unifier Cast software that allows attackers to execute arbitrary code with Loc...

May 31, 2024
CVE-2024-2771
9.8

This vulnerability allows unauthenticated attackers to escalate privileges in the Fluent Forms WordPress plugin by accessing a REST API endpoint witho...

May 18, 2024
CVE-2024-4223
9.8

The Tutor LMS WordPress plugin has a missing capability check vulnerability that allows unauthenticated attackers to add, modify, or delete data. This...

May 16, 2024
CVE-2024-27939
9.8

CVE-2024-27939 is a critical vulnerability in Siemens RUGGEDCOM CROSSBOW industrial network management software that allows unauthenticated attackers ...

May 14, 2024
CVE-2024-25912
9.8

This CVE describes an unauthenticated arbitrary WordPress settings change vulnerability in the MoveTo plugin. Attackers can modify WordPress configura...

Apr 11, 2024
CVE-2023-6875
9.8

This vulnerability allows unauthenticated attackers to bypass authentication on the POST SMTP Mailer WordPress plugin's REST API endpoint due to a typ...

Jan 11, 2024
CVE-2023-5877
9.8

The affiliate-toolkit WordPress plugin before version 3.4.3 has an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. Unauthenticated a...

Jan 1, 2024
CVE-2023-50976
9.8

Redpanda versions before 23.1.21 and 23.2.x before 23.2.18 have missing authorization checks in the Transactions API, allowing unauthorized users to p...

Dec 18, 2023
CVE-2023-48417
9.8

CVE-2023-48417 is a missing permission check vulnerability in KeyChainActivity applications that allows unauthorized access and manipulation of sensit...

Dec 11, 2023
CVE-2023-49654
9.8

The Jenkins MATLAB Plugin vulnerability allows attackers to read arbitrary XML files from the Jenkins controller file system due to missing permission...

Nov 29, 2023
CVE-2023-20252
9.8

This critical vulnerability in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to bypass authentication via SAML API flaws, gain...

Sep 27, 2023
CVE-2023-43135
9.8

This vulnerability allows unauthenticated attackers to access sensitive information and obtain user tokens on TP-LINK ER5120G routers, enabling them t...

Sep 20, 2023
CVE-2023-43134
9.8

This vulnerability in Netis 360RAC1200 routers allows unauthenticated attackers to access sensitive device information and user tokens, enabling them ...

Sep 20, 2023
CVE-2023-39073
9.8

This vulnerability in SNMP Web Pro v1.1 allows remote attackers to execute arbitrary code and access sensitive information through specially crafted r...

Sep 12, 2023
CVE-2023-36140
9.8

CVE-2023-36140 is a critical authentication vulnerability in PHPJabbers Cleaning Business Software 1.0 where user passwords are stored without encrypt...

Sep 11, 2023
CVE-2023-26301
9.8

This vulnerability affects certain HP LaserJet Pro printers that lack authentication on specific endpoints, allowing attackers to potentially gain ele...

Jul 21, 2023
CVE-2021-4381
9.8

The uListing WordPress plugin up to version 1.6.6 has an authorization bypass vulnerability that allows unauthenticated attackers to modify any WordPr...

Jun 7, 2023
CVE-2021-4362
9.8

The Kiwi Social Share WordPress plugin version 2.1.0 has an authorization bypass vulnerability that allows unauthenticated attackers to read and modif...

Jun 7, 2023
CVE-2021-4370
9.8

The uListing WordPress plugin up to version 1.6.6 has an authorization bypass vulnerability where unauthenticated users can access administrative acti...

Jun 7, 2023
CVE-2021-4343
9.8

This vulnerability in the Unauthenticated Account Creation plugin for WordPress allows unauthenticated attackers to create user accounts, including ad...

Jun 7, 2023
CVE-2021-4346
9.8

The uListing WordPress plugin up to version 1.6.6 has an authentication bypass vulnerability that allows unauthenticated attackers to modify any user ...

Jun 7, 2023
CVE-2019-25141
9.8

The Easy WP SMTP WordPress plugin up to version 1.3.9 has an authorization bypass vulnerability that allows unauthenticated attackers to modify plugin...

Jun 7, 2023
CVE-2022-48367
9.8

This vulnerability in eZ Publish Ibexa Kernel allows attackers to bypass object state-based access controls, potentially accessing restricted content....

Mar 12, 2023
CVE-2021-31577
9.8

CVE-2021-31577 is a missing permission check vulnerability in Boa web server that allows remote attackers to escalate privileges without authenticatio...

Feb 6, 2023
CVE-2022-1245
9.8

This vulnerability allows a client application with a valid access token to exchange tokens for any target client by specifying the target's client_id...

Jul 8, 2022
CVE-2022-28993
9.8

CVE-2022-28993 allows attackers to take over user accounts in Multi Store Inventory Management System v1.0 by sending specially crafted POST requests....

May 20, 2022
CVE-2022-29906
9.8

This vulnerability allows attackers to bypass authorization checks in the QuizGame extension for MediaWiki, granting unauthorized access to admin API ...

Apr 29, 2022
CVE-2021-32172
9.8

CVE-2021-32172 is a critical pre-authentication remote code execution vulnerability in Maian Cart v3.8's Elfinder plugin due to broken access control....

Oct 7, 2021
CVE-2021-33924
9.8

CVE-2021-33924 is an incorrect access control vulnerability in Confluent's cp-ansible automation tool that allows remote attackers to access sensitive...

Sep 29, 2021
CVE-2021-37270
9.8

CVE-2021-37270 is an authentication bypass vulnerability in CMS Enterprise Website Construction System 5.0 that allows unauthenticated attackers to di...

Sep 27, 2021
CVE-2021-37535
9.8

CVE-2021-37535 is a critical authorization bypass vulnerability in SAP NetWeaver Application Server Java's JMS Connector Service. It allows attackers ...

Sep 14, 2021
CVE-2021-35327
9.8

This vulnerability allows attackers to enable Telnet service on TOTOLINK A720R routers via a crafted POST request, then gain access using default cred...

Aug 5, 2021
CVE-2021-27903
9.8

CVE-2021-27903 is a remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected systems. This vulnera...

Jun 30, 2021
CVE-2021-31921
9.8

This vulnerability allows external clients to bypass Istio's authorization checks and access internal Kubernetes services they shouldn't have access t...

Jun 2, 2021
CVE-2021-22891
9.8

This critical vulnerability allows unauthenticated attackers to remotely compromise Citrix ShareFile Storage Zones Controller systems. It affects all ...

May 27, 2021
CVE-2021-28141
9.8

This CVE describes a vulnerability in Progress Telerik UI for ASP.NET AJAX that allows unauthorized access to MicrosoftAjax.js through the Telerik.Web...

Mar 11, 2021
CVE-2020-28215
9.8

CVE-2020-28215 is a missing authorization vulnerability in Schneider Electric's Easergy T300 firmware that allows attackers to bypass access controls....

Dec 11, 2020
CVE-2020-27998
9.8

CVE-2020-27998 is a critical vulnerability in FastReport versions before 2020.4.0, where the lack of a ScriptSecurity feature allows attackers to exec...

Oct 29, 2020

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 2,993 CVEs classified as CWE-862, with 212 rated critical and 815 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free