CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

2,994
Total CVEs
212
Critical
816
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 107
2 Sap 31
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Oracle 9

All Missing Authorization CVEs (2,994)

CVE-2020-25282
9.8

This vulnerability allows attackers to bypass access restrictions on property values in LG's Universal Integrated Circuit Card (lguicc) software on An...

Sep 11, 2020
CVE-2026-0509
9.6

This vulnerability allows authenticated low-privileged users in SAP NetWeaver ABAP systems to execute unauthorized background Remote Function Calls, b...

Feb 10, 2026
CVE-2025-62712
9.6

An authenticated non-privileged user in JumpServer can retrieve connection tokens belonging to all users via the super-connection API endpoint, allowi...

Oct 30, 2025
CVE-2025-52950
9.6

An unauthenticated attacker can access sensitive data and tamper with resources on Juniper Security Director due to missing authorization checks on mu...

Jul 11, 2025
CVE-2025-42989
9.6

CVE-2025-42989 is a privilege escalation vulnerability in SAP systems where authenticated users can bypass authorization checks during RFC inbound pro...

Jun 10, 2025
CVE-2025-68018
9.4

A missing authorization vulnerability in the Order Listener for WooCommerce plugin allows attackers to bypass access controls and perform unauthorized...

Jan 22, 2026
CVE-2026-24042
9.4

This vulnerability allows unauthenticated attackers to execute unpublished edit-mode actions in publicly accessible Appsmith applications. Attackers c...

Jan 22, 2026
CVE-2025-53825
9.4

CVE-2025-53825 is an unauthenticated remote code execution vulnerability in Dokploy's preview deployment feature. Any user can trigger arbitrary code ...

Jul 14, 2025
CVE-2026-25939
9.1

An authorization bypass vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to create and modify arbitrary sche...

Feb 9, 2026
CVE-2026-25810
9.1

PlaciPy placement management system version 1.0.0 has an authorization vulnerability where authenticated users can access other users' student submiss...

Feb 9, 2026
CVE-2026-25876
9.1

PlaciPy placement management system version 1.0.0 has a missing object-level authorization vulnerability that allows authenticated users to access ass...

Feb 9, 2026
CVE-2025-62754
9.1

This CVE describes a Missing Authorization vulnerability in the Payment Gateway bKash for WC WordPress plugin that allows attackers to bypass access c...

Jan 22, 2026
CVE-2025-14741
9.1

The Frontend Admin by DynamiApps WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete any conten...

Jan 9, 2026
CVE-2025-68535
9.1

This CVE describes a missing authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to bypass access controls. ...

Dec 24, 2025
CVE-2025-68508
9.1

This CVE describes a missing authorization vulnerability in the Brave Popup Builder WordPress plugin that allows attackers to bypass access controls. ...

Dec 24, 2025
CVE-2025-68511
9.1

This CVE describes a missing authorization vulnerability in the Gutenverse Form WordPress plugin that allows attackers to bypass access controls. It a...

Dec 24, 2025
CVE-2025-66131
9.1

This CVE describes a Missing Authorization vulnerability in the Yaad Sarig Payment Gateway for WooCommerce WordPress plugin. It allows attackers to ex...

Dec 16, 2025
CVE-2025-65669
9.1

CVE-2025-65669 is an authorization bypass vulnerability in classroomio 0.1.13 that allows student accounts to delete courses from the Explore page wit...

Nov 26, 2025
CVE-2025-53214
9.1

This CVE describes a Missing Authorization vulnerability in the Sertifier Certificate & Badge Maker WordPress plugin that allows attackers to bypass a...

Nov 6, 2025
CVE-2025-62919
9.1

This CVE describes a Missing Authorization vulnerability in the themeshopy TS Demo Importer WordPress plugin (ts-demo-importer) that allows attackers ...

Oct 27, 2025
CVE-2025-62892
9.1

This CVE describes a Missing Authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to access functionality not...

Oct 27, 2025
CVE-2020-36852
9.1

This vulnerability in the WordPress Custom Searchable Data Entry System plugin allows unauthenticated attackers to completely wipe critical database t...

Oct 1, 2025
CVE-2025-43773
9.1

This vulnerability in Liferay Portal and DXP allows improper access through the expandoTableLocalService, potentially enabling unauthorized data acces...

Aug 29, 2025
CVE-2025-50171
9.1

This vulnerability allows unauthorized attackers to perform spoofing attacks against Remote Desktop Server by exploiting missing authorization checks....

Aug 12, 2025
CVE-2025-6205
KEV EPSS 49.5% 9.1

A missing authorization vulnerability in DELMIA Apriso allows attackers to bypass authentication and gain privileged access to the application. This a...

Aug 4, 2025
CVE-2025-53495
9.1

This CVE describes a Missing Authorization vulnerability in MediaWiki's AbuseFilter extension that allows unauthorized users to bypass access controls...

Jul 7, 2025
CVE-2025-53499
9.1

This CVE describes a missing authorization vulnerability in Wikimedia's MediaWiki AbuseFilter extension that allows unauthorized users to bypass acces...

Jul 7, 2025
CVE-2025-30448
9.1

This vulnerability allows an attacker to enable iCloud folder sharing without proper authentication. It affects multiple Apple operating systems inclu...

May 12, 2025
CVE-2025-31685
9.1

This CVE describes a Missing Authorization vulnerability in Drupal Open Social that allows Forceful Browsing (direct access to restricted pages withou...

Mar 31, 2025
CVE-2025-27583
9.1

This vulnerability allows unauthenticated attackers to create and modify user accounts, including Administrator accounts, in Serosoft Academia SIS Eag...

Mar 3, 2025
CVE-2024-54542
9.1

This CVE describes an authentication bypass vulnerability in Apple's Private Browsing feature across multiple platforms. Attackers could access Privat...

Jan 27, 2025
CVE-2024-54369
9.1

This vulnerability allows attackers to install and activate arbitrary WordPress plugins without proper authorization. It affects all WordPress sites u...

Dec 16, 2024
CVE-2022-46838
9.1

This vulnerability allows unauthenticated attackers to change plugin settings in JS Help Desk WordPress plugin due to missing authorization checks. An...

Dec 13, 2024
CVE-2024-55879
9.1

This vulnerability allows any XWiki user with script rights to execute arbitrary remote code by adding XWiki.ConfigurableClass instances to pages. Thi...

Dec 12, 2024
CVE-2024-53810
9.1

This CVE describes a broken access control vulnerability in the Simple User Registration WordPress plugin that allows unauthorized users to delete use...

Dec 6, 2024
CVE-2024-7475
9.1

This vulnerability allows unauthorized attackers to modify SAML configuration settings in lunary-ai/lunary version 1.3.2. This can lead to authenticat...

Oct 29, 2024
CVE-2024-7856
9.1

This vulnerability in the MP3 Audio Player WordPress plugin allows authenticated attackers with subscriber-level access or higher to delete arbitrary ...

Aug 29, 2024
CVE-2024-45168
9.1

CVE-2024-45168 is a critical authentication bypass vulnerability in UCI IDOL 2 software where data is transmitted over raw sockets without authenticat...

Aug 22, 2024
CVE-2023-39312
9.1

This CVE describes a missing authorization vulnerability in the Avada WordPress theme that allows authenticated users with author-level permissions to...

Jun 19, 2024
CVE-2024-33565
9.1

This CVE describes an unauthenticated broken access control vulnerability in the UkrSolution Barcode Scanner with Inventory & Order Manager WordPress ...

Jun 9, 2024
CVE-2024-32948
9.1

This CVE describes a Missing Authorization vulnerability in the ARMember WordPress plugin that allows unauthorized users to access privileged function...

Apr 24, 2024
CVE-2023-36621
9.1

This vulnerability in the Boomerang Parental Control Android app allows children to bypass parental restrictions by entering Android's Safe Mode, wher...

Nov 3, 2023
CVE-2023-44208
9.1

This vulnerability in Acronis Cyber Protect Home Office for Windows allows unauthorized users to access and manipulate sensitive information due to mi...

Oct 4, 2023
CVE-2023-41296
9.1

This CVE-2023-41296 is a missing authorization vulnerability in a Huawei kernel module that allows unauthorized access to kernel functions. Successful...

Sep 25, 2023
CVE-2021-4374
9.1

This vulnerability in the WordPress Automatic Plugin allows unauthenticated attackers to modify any WordPress site setting without authorization. It a...

Jun 7, 2023
CVE-2023-26957
9.1

Onekeyadmin v1.3.9 contains an arbitrary file deletion vulnerability in the plugins controller component. This allows authenticated attackers to delet...

Mar 9, 2023
CVE-2020-4926
9.1

This vulnerability in IBM Spectrum Scale 5.1 and Elastic Storage System 6.1 allows unauthorized access to user data or injection of arbitrary data thr...

May 24, 2022
CVE-2022-0871
9.1

CVE-2022-0871 is a missing authorization vulnerability in Gogs (a self-hosted Git service) that allows attackers to bypass authentication and access u...

Mar 11, 2022
CVE-2022-23944
9.1

Apache ShenYu versions 2.4.0 and 2.4.1 have an authentication bypass vulnerability in the /plugin API endpoint. This allows unauthenticated attackers ...

Jan 25, 2022
CVE-2021-39231
9.1

Apache Ozone versions before 1.2.0 expose internal RPC endpoints that allow attackers to download raw data from Datanode and Ozone Manager components,...

Nov 19, 2021

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 2,994 CVEs classified as CWE-862, with 212 rated critical and 816 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free