CWE-862Class3 in KEV

Missing Authorization

Incomplete in the CWE catalog · 7,511 CVEs mapped

7,511
CVEs mapped
3
In KEV
5.4
Median CVSS
What it is

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Recent examples
4.3cvss
CVE-2026-86499

In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission

In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission

MEDIUMno explanation yet
epss
4.3cvss
CVE-2026-86496

In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses

In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses

MEDIUMno explanation yet
epss
6.5cvss
CVE-2026-86495

In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects

In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects

MEDIUMno explanation yet
epss
The record
Technical detail
CWE ID
CWE-862
Abstraction
Class
Structure
Simple
Status
Incomplete
References (6)