← Back
CWE-862

8,729 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,729)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Aug 7, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
1Metersphere
1Metersphere
Jun 17, 2026
Aug 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers....Show more
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue.Show less
1Palantir
1Foundry Campaigns
Jun 17, 2026
Aug 3, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
1Answer
1Answer
Jun 17, 2026
Aug 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.
1Liferay
2Digital Experience Platform
Liferay Portal
Jun 17, 2026
Aug 2, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organization...Show more
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.Show less
1Jeesite
1Jeesite
Jun 17, 2026
Jul 31, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Administrator's role information.
6Backupbliss
Copy Delete PostsInisev+3 more
11Backup Migration
CloneDuplicate Post+8 more
Jun 17, 2026
Jul 28, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton...Show more
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to install select plugins from Inisev on vulnerable sites. CVE-2023-38514 appears to be a duplicate of this vulnerability.Show less
1Tolgee
1Tolgee
Jun 17, 2026
Jul 27, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request is made using an API key, the backend fails to verify the permission scopes associated with the key,...Show more
Tolgee is an open-source localization platform. Starting in version 3.14.0 and prior to version 3.23.1, when a request is made using an API key, the backend fails to verify the permission scopes associated with the key, effectively bypassing permission checks entirely for some endpoints. It's important to note that this vulnerability only affects projects that have inadvertently exposed their API keys on the internet. Projects that have kept their API keys secure are not impacted. This issue is fixed in version 3.23.1.Show less
1Instawp
1Instawp Connect
Jun 17, 2026
Jul 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and incl...Show more
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This makes it possible for unauthenticated attackers to add, modify or delete post and taxonomy, install, activate or deactivate plugin, change customizer settings, add or modify or delete user including administrator user.Show less
1Jenkins
1Servicenow Devops
Jun 17, 2026
Jul 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To addres...Show more
A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform. Show less
1Gxsoftware
1Xperiencentral
Jun 17, 2026
Jul 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthorized user is able to bypass other security filters they are able to post...Show more
POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthorized user is able to bypass other security filters they are able to post unauthorized data to the server because of CVE-2022-22965.Show less
1Emlog
1Emlog
Jun 17, 2026
Jul 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
1Hp
19Color Laserjet Pro 4201 4203 4ra87f Firmware
Color Laserjet Pro 4201 4203 4ra88f FirmwareColor Laserjet Pro 4201 4203 4ra89a Firmware+16 more
Jun 17, 2026
Jul 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclosure related to a lack of authentication with certain endpoints.
1Hashicorp
1Nomad
Jun 17, 2026
Jul 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4...Show more
HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4.1.Show less
1Hashicorp
1Nomad
Jun 17, 2026
Jul 20, 2023
N/A· v4
3.8 LOW· v3
N/A· v2
HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
1Hazelcast
2Hazelcast
Imdg
Jun 17, 2026
Jul 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions g...Show more
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.Show less
1Metagauss
1Profilegrid
Jun 17, 2026
Jul 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for au...Show more
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3.Show less
1Metagauss
1Profilegrid
Jun 17, 2026
Jul 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. Thi...Show more
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily. This can be used by attackers to achieve privilege escalation.Show less
1Metagauss
1Profilegrid
Jun 17, 2026
Jul 18, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible fo...Show more
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and update existing users.Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Jul 17, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the update...Show more
Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions. Show less