← Back
CWE-862

8,732 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,732)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Sep 4, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In Ifaa service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed
1Xwiki
1Xwiki
Jun 17, 2026
Sep 1, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible in XWiki to execute Velocity code without having script right by creating an XClass with a property...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible in XWiki to execute Velocity code without having script right by creating an XClass with a property of type "TextArea" and content type "VelocityCode" or "VelocityWiki". For the former, the syntax of the document needs to be set the `xwiki/1.0` (this syntax doesn't need to be installed). In both cases, when adding the property to an object, the Velocity code is executed regardless of the rights of the author of the property (edit right is still required, though). In both cases, the code is executed with the correct context author so no privileged APIs can be accessed. However, Velocity still grants access to otherwise inaccessible data and APIs that could allow further privilege escalation. At least for "VelocityCode", this behavior is most likely very old but only since XWiki 7.2, script right is a separate right, before that version all users were allowed to execute Velocity and thus this was expected and not a security issue. This has been patched in XWiki 14.10.10 and 15.4 RC1. Users are advised to upgrade. There are no known workarounds.Show less
1Github
1Enterprise Server
Jun 17, 2026
Sep 1, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access to an upstream repository after its visibility was changed to private....Show more
An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access to an upstream repository after its visibility was changed to private. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.10.0 and was fixed in versions 3.9.4, 3.8.9, 3.7.16 and 3.6.18. This vulnerability was reported via the GitHub Bug Bounty program. Show less
1Bludit
1Bludit
Jun 17, 2026
Sep 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.
1Acronis
1Agent
Jun 17, 2026
Aug 31, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 32047.
1Rednao
1Woocommerce Pdf Invoice Builder
Jun 17, 2026
Aug 31, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it po...Show more
The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice id.Show less
1Plugin
1Waiting
Jun 17, 2026
Aug 31, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenti...Show more
The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns as well as manipulate other plugin settings.Show less
1Sureshchand
1Chp Ads Block Detector
Jun 17, 2026
Aug 31, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a missing capability check on the chp_abd_action function in versions up to, and including, 3.9.4. Thi...Show more
The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a missing capability check on the chp_abd_action function in versions up to, and including, 3.9.4. This makes it possible for subscriber-level attackers to change or reset plugin settings. CVE-2023-36509 appears to be a duplicate of this issue.Show less
1Badgeos
1Badgeos
Jun 17, 2026
Aug 31, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to, and including, 3.7.1.6. This makes it po...Show more
The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to, and including, 3.7.1.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the plugin's log entries.Show less
1Skylark
1Skylark
Jun 17, 2026
Aug 25, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead a user to access an arbitrary website...Show more
Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead a user to access an arbitrary website via another application installed on the user's device.Show less
1Enalean
1Tuleap
Jun 17, 2026
Aug 24, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-...Show more
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-3, the preview of an artifact link with a type does not respect the project, tracker and artifact level permissions. The issue occurs on the artifact view (not reproducible on the artifact modal). Users might get access to information they should not have access to. Only the title, status, assigned to and last update date fields as defined by the semantics are impacted. If those fields have strict permissions (e.g. the title is only visible to a specific user group) those permissions are still enforced. Tuleap Community Edition 14.11.99.28, Tuleap Enterprise Edition 14.10-6, and Tuleap Enterprise Edition 14.11-3 contain a fix for this issue.Show less
1Spice Space
1Spice Server
Jun 17, 2026
Aug 22, 2023
N/A· v4
8.6 HIGH· v3
N/A· v2
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known...Show more
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.Show less
1Jenkins
1Fortify
Jun 17, 2026
Aug 21, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through ano...Show more
A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. Show less
1Hamza417
1Inure
Jun 17, 2026
Aug 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Missing Authorization in GitHub repository hamza417/inure prior to build88.
1Wphappycoders
1Comments Like Dislike
Jun 17, 2026
Aug 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and includ...Show more
The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to reset the plugin's settings. NOTE: this issue is was only partially patched in version 1.2.0, as the nonce is still present to subscriber-level users.Show less
1Jenkins
1Delphix
Jun 17, 2026
Aug 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Recruit
1Rikunabi Next
Jun 17, 2026
Aug 16, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a malicious intent to lead the vulnerable App to access an arbitrary website.