Threats Tagged 'cwe-862'
View all threats tagged with 'cwe-862'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-862'
Click on any threat for detailed analysis and mitigation recommendations
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools are listed but are not rechecked when a tools/call request is dispatched. A client that knows a hidden tool name can directly invoke excluded read, write, or delete tools despite the operator's configured least-privilege restrictions. The advisory traces the vulnerable input and processing flow through ENABLED_TOOLS, TOOLSETS, tools/list, tools/call, and _call_tool_mcp, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0. Join the discussion | CVE Database V5 | 09/22/2026, 17:57:26 UTC Added: 09/22/2026, 18:18:24 UTC |
CVE-2026-77244 is an improper authentication vulnerability in the MCP Atlassian server used for Atlassian products like Confluence and Jira. Versions prior to 0.22.0 accept HTTP requests without verifying user identity, causing the server to use the operator's global Jira or Confluence credentials for downstream operations. This allows any network client with access to the MCP endpoint to perform read and write actions as the operator. The vulnerability is fixed in version 0.22.0. Join the discussion | CVE Database V5 | 09/22/2026, 17:49:38 UTC Added: 09/22/2026, 18:03:27 UTC |
0 CVE-2026-94384 is a missing authorization vulnerability in the sfExecuteAWSService Lambda function of the Amazon Connect Salesforce Lambda application. This function, used only during initial setup, improperly dispatches caller-supplied parameters to privileged AWS service APIs without validating authorization. Consequently, any IAM principal with lambda:InvokeFunction permission on this function can perform AWS operations beyond their own IAM permissions. Versions from 5.15 through 5.24.16 are affected. The issue is remediated by upgrading to version 5.26 or later, deleting or disabling the vulnerable function after setup, or restricting invocation permissions tightly. Join the discussion | AWS Security Bulletins | 09/22/2026, 17:10:17 UTC Added: 09/22/2026, 17:14:55 UTC |
Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards attacker-selected message topics to the dispatcher without checking the authenticated user's role because the nginx authentication subrequest does not provide role-aware authorization to the handler. Any authenticated viewer can send admin-only topics such as restart, notifications/set, and camera detection, recording, snapshot, audio, motion, and enablement settings, causing service restarts or disabling security monitoring functions. Authentication must be enabled and valid viewer credentials are required. This issue is fixed in version 0.17.2. Join the discussion | CVE Database V5 | 09/22/2026, 15:35:23 UTC Added: 09/22/2026, 15:48:20 UTC |
The ThumbPress WordPress plugin up to version 6.2.1 has a missing authorization vulnerability in the send_deactivation_survey() function. This flaw allows authenticated users with Subscriber-level access or higher to deactivate the plugin via a crafted AJAX request without proper capability checks or nonce verification. Join the discussion | CVE Database V5 | 09/22/2026, 07:41:15 UTC Added: 09/22/2026, 08:03:18 UTC |
0 The WP User Manager plugin for WordPress versions up to and including 2.9.18 contains a missing authorization vulnerability. This flaw allows authenticated users with Subscriber-level access or higher to modify Stripe integration settings without proper capability checks. The vulnerability arises because the Connect::complete() function, triggered on the admin_init hook, lacks current_user_can() and nonce verification. Exploitation enables attackers to hijack the site's Stripe payments by completing their own Stripe Connect OAuth flow and redirecting payments to their Stripe account. Join the discussion | CVE Database V5 | 09/22/2026, 07:41:15 UTC Added: 09/22/2026, 08:03:16 UTC |
The Handily WordPress plugin up to version 1.0.3 has a missing authorization vulnerability allowing unauthenticated attackers to modify Stripe payment settings. This includes changing publishable keys, secret keys, email addresses, and redirect URLs, potentially redirecting payments to attacker-controlled Stripe accounts. The vulnerability is identified as CWE-862 and has a medium severity with a CVSS score of 5.3. Join the discussion | CVE Database V5 | 09/22/2026, 07:41:14 UTC Added: 09/22/2026, 08:03:16 UTC |
The wpForo Forum plugin for WordPress contains an authorization bypass vulnerability in all versions up to and including 3.1.5. This flaw allows authenticated users with subscriber-level access or higher to modify guest authors' forum posts, including the title, body, author name, and stored owner email address. Exploitation requires that guest posting and editing features are enabled and that the attacker knows the target guest author's email address. Join the discussion | CVE Database V5 | 09/22/2026, 07:41:13 UTC Added: 09/22/2026, 08:03:18 UTC |
0 The RW Elephant Rental Inventory WordPress plugin up to version 2.3.13 contains a missing authorization vulnerability. The toggle_cache() function, accessible via an AJAX action, lacks proper capability checks and nonce verification. This allows authenticated users with Subscriber-level access or higher to toggle the plugin's cache setting via a crafted POST request. Join the discussion | CVE Database V5 | 09/22/2026, 07:41:11 UTC Added: 09/22/2026, 08:03:18 UTC |
The Image Buzz WordPress plugin up to version 1.0.3 has a missing authorization vulnerability allowing unauthenticated attackers to modify API keys for Pixabay, Unsplash, and Pixels. This flaw enables unauthorized changes to API keys configured by site administrators. Join the discussion | CVE Database V5 | 09/22/2026, 07:41:10 UTC Added: 09/22/2026, 08:03:16 UTC |
Showing 1 to 10 of 3569 results