← Back
CWE-862

8,736 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,736)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Scriptler
Jun 17, 2026
Dec 13, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read permission to read the contents of a Groovy script by knowing its ID.
1Relyum
2Rely Pcie Firmware
Rely Rec Firmware
Jun 17, 2026
Dec 13, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged user to execute administrative functions.
1Google
1Chromecast Firmware
Jun 17, 2026
Dec 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
2Quarkus
Redhat
2Build Of Quarkus
Quarkus
Jun 17, 2026
Dec 9, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the en...Show more
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.Show less
1Google
1Android
Jun 17, 2026
Dec 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...Show more
In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
1Enbw
1Senec Storage Box Firmware
Jun 17, 2026
Dec 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.
1Bowo
1System Dashboard
Jun 17, 2026
Dec 7, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7...Show more
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve data key specs.Show less
1Bowo
1System Dashboard
Jun 17, 2026
Dec 7, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2...Show more
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve potentially sensitive option values, and deserialize the content of those values.Show less
1Bowo
1System Dashboard
Jun 17, 2026
Dec 7, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2...Show more
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive global value information.Show less
1Bowo
1System Dashboard
Jun 17, 2026
Dec 7, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7...Show more
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information provided by PHP info.Show less
1Bowo
1System Dashboard
Jun 17, 2026
Dec 7, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8....Show more
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information such as database credentials.Show less
1Myprestamodules
1Orders (csv, Excel) Export Pro
Jun 17, 2026
Dec 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can...Show more
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer/ps_address tables such as name / surname / email / phone number / full postal address.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Dec 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges...Show more
In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalati...Show more
In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
4Google
LinuxfoundationOpenwrt+1 more
4Android
OpenwrtRdk B+1 more
Jun 17, 2026
Dec 4, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.Show less
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges need...Show more
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges neededShow less
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Dec 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed