On this page

CWE-862: Missing Authorization

Weakness Summary

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

  • Canonical source: MITRE CWE-862 (opens in a new tab)
  • Published Atomicorp CVE observations: 38
  • Distinct affected products in those observations: 36
  • Active Atomicorp rules associated with this weakness: 62

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2025-45854JEHC-BPM - Remote Code Executejehc-bpmAttack Blocked by Atomicorp344363 , 390724
CVE-2026-33712TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controlstypebot.ioAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34976Dgraph <=v25.3.0 - Admin Mutation Missing AuthorizationdgraphDetected by Atomicorp398008
CVE-2026-45632Dokploy: Schedule Authorization Bypass Enables Host/Server Command ExecutiondokployAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72868Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injectiondokployAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*dokployAttack Blocked by Atomicorp340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2018-1217Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Controlemc avamarAttack Blocked by Atomicorp391213
CVE-2019-25141Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Updateeasy wp smtpAttack Blocked by Atomicorp390726 , 392647
CVE-2020-10257ThemeREX Addons - Remote Code ExecutionthemerexDetected by Atomicorp377360
CVE-2021-21307Lucee Admin - Remote Code Executionlucee serverAttack Blocked by Atomicorp340149 , 342259 , 344364 , 344366 , 350147
CVE-2021-21978VMware View Planner <4.6 SP1- Remote Code Executionview plannerAttack Blocked by Atomicorp330791 , 340007 , 340152
CVE-2021-45467Control Web Panel (CWP) - File InclusionwebpanelAttack Blocked by Atomicorp320464 , 320465 , 390613 , 390614
CVE-2022-1574WordPress HTML2WP <=1.0.0 - Arbitrary File Uploadhtml2wpAttack Blocked by Atomicorp382238
CVE-2022-36642Omnia MPX 1.5.0+r1 - Local File Inclusionomnia mpx node firmwareAttack Blocked by Atomicorp340007 , 344360 , 347009
CVE-2023-26035ZoneMinder Snapshots - Command InjectionzoneminderAttack Blocked by Atomicorp344364 , 344366
CVE-2024-9234GutenKit <= 2.1.0 - Arbitrary File UploadgutenkitAttack Blocked by Atomicorp340162 , 340163
CVE-2025-11833Post SMTP <= 3.6.0 - Email Log Disclosurepost smtp mailerDetected by Atomicorp377360
CVE-2025-1562Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Controlfunnelkit automationsDetected by Atomicorp377360
CVE-2025-70150membership management system Missing Authorization Vulnerabilitymembership management systemAttack Blocked by Atomicorp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-49819UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdUpSnapAttack Blocked by Atomicorp340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-47754unauthenticated path traversal in Metacat 2.xmetacatAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2018-10093AudioCodes 420HD - Remote Code Execution420hd ip phone firmwareAttack Blocked by Atomicorp344360 , 347009
CVE-2022-1329Elementor Website Builder - Remote Code Executionwebsite builderDetected by Atomicorp377360
CVE-2022-4223pgAdmin < 6.17 - Unauthenticated Remote Code Executionpgadmin 4Attack Blocked by Atomicorp393655
CVE-2023-49230Peplink Balance Two before 8.4.0 - Unauthenticated Config Uploadbalance two firmwareAttack Blocked by Atomicorp330791 , 340152 , 392301
CVE-2023-52163Digiever DS-2105 Pro - Command Injectionds-2105 pro firmwareAttack Blocked by Atomicorp390709
CVE-2024-30464WPZOOM Social Icons Widget <= 4.2.15 - Missing Authorizationsocial-icons-widget-by-wpzoomDetected by Atomicorp377360
CVE-2025-2075Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalationuncanny automatorDetected by Atomicorp377360
CVE-2026-46518OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographicsopenemrAttack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-47394PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validatePraisonAIAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-86438Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install ActionlaradashboardAttack Blocked by Atomicorp340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73658Trigger.dev: Cross-tenant object store read and write via URL path traversaltrigger.devAttack Blocked by Atomicorp347009
CVE-2026-63464Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_privatenebula-meshAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2023-6020Ray Static File - Local File InclusionrayAttack Blocked by Atomicorp347009
CVE-2023-6038H2O ImportFiles - Local File Inclusionh2oAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2026-85512SourceCodester Class and Exam Timetabling System session.php authorizationClass and Exam Timetabling SystemAttack Blocked by Atomicorp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-3335Canto <= 3.1.1 - Missing Authorization to Unauthenticated File UploadCantoAttack Blocked by Atomicorp300007
CVE-2021-25075WordPress Duplicate Page or Post <1.5.1 - Cross-Site Scriptingduplicate page or postAttack Blocked by Atomicorp346755 , 377360

Associated Atomicorp WAF Rules

RuleStatusBehavior
300007Activedisruptive (deny)
320464Activedisruptive (deny)
320465Activedisruptive (deny)
330791Activedisruptive (deny)
333140Activedisruptive (deny)
333141Activedisruptive (deny)
337109Activedisruptive (deny)
337110Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340016Activedisruptive (deny)
340017Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340095Activedisruptive (deny)
340144Activedisruptive (deny)
340145Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340149Activedisruptive (deny)
340152Activedisruptive (deny)
340156Activedisruptive (deny)
340157Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340165Activedisruptive (deny)
340193Activedisruptive (deny)
341145Activedisruptive (deny)
341245Activedisruptive (deny)
341256Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
346755Activedisruptive (deny)
347009Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
377360Activenon-disruptive (pass)
380026Activedisruptive (deny)
380122Activedisruptive (deny)
382238Activedisruptive (deny)
390572Activedisruptive (deny)
390613Activedisruptive (deny)
390614Activedisruptive (deny)
390709Activedisruptive (deny)
390722Activedisruptive (deny)
390724Activedisruptive (deny)
390726Activedisruptive (deny)
391213Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
393655Activedisruptive (deny)
398001Activenon-disruptive (pass)
398008Activenon-disruptive (pass)
398021Activedisruptive (deny)
398022Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-665 (opens in a new tab)