CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (2,993)
The File Manager WordPress plugin versions up to 3.0 contain an authorization bypass vulnerability that allows unauthenticated attackers to download a...
Oct 16, 2024This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to fully compromise the ser...
Oct 15, 2024The Hunk Companion WordPress plugin has an unauthenticated REST API vulnerability that allows attackers to install and activate arbitrary plugins. Thi...
Oct 11, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files and install/activate arbitrary plugins on WordPress sites using the Gute...
Oct 11, 2024This vulnerability in the MultiVendorX WordPress plugin allows unauthenticated attackers to perform privilege escalation and account takeover attacks....
Sep 4, 2024This CVE describes a Missing Authorization vulnerability in SAMPAŞ Holding's AKOS services that allows unauthorized data collection. Attackers can ex...
Sep 3, 2024This vulnerability allows unauthorized users to obtain logon tokens via a REST endpoint when Single Sign-On is enabled with Enterprise authentication ...
Aug 13, 2024CVE-2024-6806 is a critical authorization bypass vulnerability in NI VeriStand Gateway that allows unauthorized actors to access project resources. Th...
Jul 22, 2024The WooCommerce Social Login plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to register account...
Jul 20, 2024The MStore API WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user by exp...
Jul 12, 2024This vulnerability allows unauthenticated attackers to modify arbitrary WordPress site options and create administrator accounts via the InstaWP Conne...
Jun 12, 2024CVE-2024-31244 is a Missing Authorization vulnerability in the Bricksforge WordPress plugin that allows unauthenticated attackers to change arbitrary ...
Jun 9, 2024This CVE describes a missing authorization vulnerability in Unifier and Unifier Cast software that allows attackers to execute arbitrary code with Loc...
May 31, 2024This vulnerability allows unauthenticated attackers to escalate privileges in the Fluent Forms WordPress plugin by accessing a REST API endpoint witho...
May 18, 2024The Tutor LMS WordPress plugin has a missing capability check vulnerability that allows unauthenticated attackers to add, modify, or delete data. This...
May 16, 2024CVE-2024-27939 is a critical vulnerability in Siemens RUGGEDCOM CROSSBOW industrial network management software that allows unauthenticated attackers ...
May 14, 2024This CVE describes an unauthenticated arbitrary WordPress settings change vulnerability in the MoveTo plugin. Attackers can modify WordPress configura...
Apr 11, 2024This vulnerability allows unauthenticated attackers to bypass authentication on the POST SMTP Mailer WordPress plugin's REST API endpoint due to a typ...
Jan 11, 2024The affiliate-toolkit WordPress plugin before version 3.4.3 has an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. Unauthenticated a...
Jan 1, 2024Redpanda versions before 23.1.21 and 23.2.x before 23.2.18 have missing authorization checks in the Transactions API, allowing unauthorized users to p...
Dec 18, 2023CVE-2023-48417 is a missing permission check vulnerability in KeyChainActivity applications that allows unauthorized access and manipulation of sensit...
Dec 11, 2023The Jenkins MATLAB Plugin vulnerability allows attackers to read arbitrary XML files from the Jenkins controller file system due to missing permission...
Nov 29, 2023This critical vulnerability in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to bypass authentication via SAML API flaws, gain...
Sep 27, 2023This vulnerability allows unauthenticated attackers to access sensitive information and obtain user tokens on TP-LINK ER5120G routers, enabling them t...
Sep 20, 2023This vulnerability in Netis 360RAC1200 routers allows unauthenticated attackers to access sensitive device information and user tokens, enabling them ...
Sep 20, 2023This vulnerability in SNMP Web Pro v1.1 allows remote attackers to execute arbitrary code and access sensitive information through specially crafted r...
Sep 12, 2023CVE-2023-36140 is a critical authentication vulnerability in PHPJabbers Cleaning Business Software 1.0 where user passwords are stored without encrypt...
Sep 11, 2023This vulnerability affects certain HP LaserJet Pro printers that lack authentication on specific endpoints, allowing attackers to potentially gain ele...
Jul 21, 2023The uListing WordPress plugin up to version 1.6.6 has an authorization bypass vulnerability that allows unauthenticated attackers to modify any WordPr...
Jun 7, 2023The Kiwi Social Share WordPress plugin version 2.1.0 has an authorization bypass vulnerability that allows unauthenticated attackers to read and modif...
Jun 7, 2023The uListing WordPress plugin up to version 1.6.6 has an authorization bypass vulnerability where unauthenticated users can access administrative acti...
Jun 7, 2023This vulnerability in the Unauthenticated Account Creation plugin for WordPress allows unauthenticated attackers to create user accounts, including ad...
Jun 7, 2023The uListing WordPress plugin up to version 1.6.6 has an authentication bypass vulnerability that allows unauthenticated attackers to modify any user ...
Jun 7, 2023The Easy WP SMTP WordPress plugin up to version 1.3.9 has an authorization bypass vulnerability that allows unauthenticated attackers to modify plugin...
Jun 7, 2023This vulnerability in eZ Publish Ibexa Kernel allows attackers to bypass object state-based access controls, potentially accessing restricted content....
Mar 12, 2023CVE-2021-31577 is a missing permission check vulnerability in Boa web server that allows remote attackers to escalate privileges without authenticatio...
Feb 6, 2023This vulnerability allows a client application with a valid access token to exchange tokens for any target client by specifying the target's client_id...
Jul 8, 2022CVE-2022-28993 allows attackers to take over user accounts in Multi Store Inventory Management System v1.0 by sending specially crafted POST requests....
May 20, 2022This vulnerability allows attackers to bypass authorization checks in the QuizGame extension for MediaWiki, granting unauthorized access to admin API ...
Apr 29, 2022CVE-2021-32172 is a critical pre-authentication remote code execution vulnerability in Maian Cart v3.8's Elfinder plugin due to broken access control....
Oct 7, 2021CVE-2021-33924 is an incorrect access control vulnerability in Confluent's cp-ansible automation tool that allows remote attackers to access sensitive...
Sep 29, 2021CVE-2021-37270 is an authentication bypass vulnerability in CMS Enterprise Website Construction System 5.0 that allows unauthenticated attackers to di...
Sep 27, 2021CVE-2021-37535 is a critical authorization bypass vulnerability in SAP NetWeaver Application Server Java's JMS Connector Service. It allows attackers ...
Sep 14, 2021This vulnerability allows attackers to enable Telnet service on TOTOLINK A720R routers via a crafted POST request, then gain access using default cred...
Aug 5, 2021CVE-2021-27903 is a remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected systems. This vulnera...
Jun 30, 2021This vulnerability allows external clients to bypass Istio's authorization checks and access internal Kubernetes services they shouldn't have access t...
Jun 2, 2021This critical vulnerability allows unauthenticated attackers to remotely compromise Citrix ShareFile Storage Zones Controller systems. It affects all ...
May 27, 2021This CVE describes a vulnerability in Progress Telerik UI for ASP.NET AJAX that allows unauthorized access to MicrosoftAjax.js through the Telerik.Web...
Mar 11, 2021CVE-2020-28215 is a missing authorization vulnerability in Schneider Electric's Easergy T300 firmware that allows attackers to bypass access controls....
Dec 11, 2020CVE-2020-27998 is a critical vulnerability in FastReport versions before 2020.4.0, where the lack of a ScriptSecurity feature allows attackers to exec...
Oct 29, 2020About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 2,993 CVEs classified as CWE-862, with 212 rated critical and 815 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free