On this page
CWE-862: Missing Authorization
Weakness Summary
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- Canonical source: MITRE CWE-862 (opens in a new tab)
- Published Atomicorp CVE observations: 38
- Distinct affected products in those observations: 36
- Active Atomicorp rules associated with this weakness: 62
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2025-45854 | JEHC-BPM - Remote Code Execute | jehc-bpm | Attack Blocked by Atomicorp | 344363 , 390724 |
| CVE-2026-33712 | TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls | typebot.io | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34976 | Dgraph <=v25.3.0 - Admin Mutation Missing Authorization | dgraph | Detected by Atomicorp | 398008 |
| CVE-2026-45632 | Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution | dokploy | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72868 | Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection | dokploy | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72876 | Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* | dokploy | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2018-1217 | Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control | emc avamar | Attack Blocked by Atomicorp | 391213 |
| CVE-2019-25141 | Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update | easy wp smtp | Attack Blocked by Atomicorp | 390726 , 392647 |
| CVE-2020-10257 | ThemeREX Addons - Remote Code Execution | themerex | Detected by Atomicorp | 377360 |
| CVE-2021-21307 | Lucee Admin - Remote Code Execution | lucee server | Attack Blocked by Atomicorp | 340149 , 342259 , 344364 , 344366 , 350147 |
| CVE-2021-21978 | VMware View Planner <4.6 SP1- Remote Code Execution | view planner | Attack Blocked by Atomicorp | 330791 , 340007 , 340152 |
| CVE-2021-45467 | Control Web Panel (CWP) - File Inclusion | webpanel | Attack Blocked by Atomicorp | 320464 , 320465 , 390613 , 390614 |
| CVE-2022-1574 | WordPress HTML2WP <=1.0.0 - Arbitrary File Upload | html2wp | Attack Blocked by Atomicorp | 382238 |
| CVE-2022-36642 | Omnia MPX 1.5.0+r1 - Local File Inclusion | omnia mpx node firmware | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 |
| CVE-2023-26035 | ZoneMinder Snapshots - Command Injection | zoneminder | Attack Blocked by Atomicorp | 344364 , 344366 |
| CVE-2024-9234 | GutenKit <= 2.1.0 - Arbitrary File Upload | gutenkit | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2025-11833 | Post SMTP <= 3.6.0 - Email Log Disclosure | post smtp mailer | Detected by Atomicorp | 377360 |
| CVE-2025-1562 | Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control | funnelkit automations | Detected by Atomicorp | 377360 |
| CVE-2025-70150 | membership management system Missing Authorization Vulnerability | membership management system | Attack Blocked by Atomicorp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-49819 | UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd | UpSnap | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-47754 | unauthenticated path traversal in Metacat 2.x | metacat | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2018-10093 | AudioCodes 420HD - Remote Code Execution | 420hd ip phone firmware | Attack Blocked by Atomicorp | 344360 , 347009 |
| CVE-2022-1329 | Elementor Website Builder - Remote Code Execution | website builder | Detected by Atomicorp | 377360 |
| CVE-2022-4223 | pgAdmin < 6.17 - Unauthenticated Remote Code Execution | pgadmin 4 | Attack Blocked by Atomicorp | 393655 |
| CVE-2023-49230 | Peplink Balance Two before 8.4.0 - Unauthenticated Config Upload | balance two firmware | Attack Blocked by Atomicorp | 330791 , 340152 , 392301 |
| CVE-2023-52163 | Digiever DS-2105 Pro - Command Injection | ds-2105 pro firmware | Attack Blocked by Atomicorp | 390709 |
| CVE-2024-30464 | WPZOOM Social Icons Widget <= 4.2.15 - Missing Authorization | social-icons-widget-by-wpzoom | Detected by Atomicorp | 377360 |
| CVE-2025-2075 | Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | uncanny automator | Detected by Atomicorp | 377360 |
| CVE-2026-46518 | OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics | openemr | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-47394 | PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate | PraisonAI | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-86438 | Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action | laradashboard | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73658 | Trigger.dev: Cross-tenant object store read and write via URL path traversal | trigger.dev | Attack Blocked by Atomicorp | 347009 |
| CVE-2026-63464 | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_private | nebula-mesh | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2023-6020 | Ray Static File - Local File Inclusion | ray | Attack Blocked by Atomicorp | 347009 |
| CVE-2023-6038 | H2O ImportFiles - Local File Inclusion | h2o | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2026-85512 | SourceCodester Class and Exam Timetabling System session.php authorization | Class and Exam Timetabling System | Attack Blocked by Atomicorp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-3335 | Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload | Canto | Attack Blocked by Atomicorp | 300007 |
| CVE-2021-25075 | WordPress Duplicate Page or Post <1.5.1 - Cross-Site Scripting | duplicate page or post | Attack Blocked by Atomicorp | 346755 , 377360 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 300007 | Active | disruptive (deny) |
| 320464 | Active | disruptive (deny) |
| 320465 | Active | disruptive (deny) |
| 330791 | Active | disruptive (deny) |
| 333140 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 337109 | Active | disruptive (deny) |
| 337110 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340144 | Active | disruptive (deny) |
| 340145 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340149 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340157 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341145 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380026 | Active | disruptive (deny) |
| 380122 | Active | disruptive (deny) |
| 382238 | Active | disruptive (deny) |
| 390572 | Active | disruptive (deny) |
| 390613 | Active | disruptive (deny) |
| 390614 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390724 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 391213 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 398001 | Active | non-disruptive (pass) |
| 398008 | Active | non-disruptive (pass) |
| 398021 | Active | disruptive (deny) |
| 398022 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims: