← Back
CWE-862

8,733 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Assembla Auth
Jun 17, 2026
Sep 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if...Show more
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.Show less
1Jenkins
1Aws Codecommit Trigger
Jun 17, 2026
Sep 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to clear the SQS queue.
1Jenkins
1Aws Codecommit Trigger
Jun 17, 2026
Sep 6, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins.
1Cerebrate Project
1Cerebrate
Jun 17, 2026
Sep 5, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
1Cozmoslabs
1Profile Builder
Jun 17, 2026
Sep 4, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the...Show more
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blogShow less
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...Show more
In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; Issue ID: ALPS08017764.Show less
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for expl...Show more
In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550; Issue ID: ALPS07978550.Show less
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed fo...Show more
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951413.Show less
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed fo...Show more
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951402.Show less
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges