← Back
CWE-862

8,723 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,723)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Jun 28, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no...Show more
In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-273906410Show less
1Google
1Android
Jun 17, 2026
Jun 28, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional exec...Show more
In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262741858Show less
1Google
1Android
Jun 17, 2026
Jun 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS service due to a missing permission check. This could lead to local escalation of privilege with no addit...Show more
In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS service due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-270050709References: N/AShow less
1Subscribe2 Project
1Subscribe2
Jun 17, 2026
Jun 28, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible f...Show more
The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary content and attachments to site users.Show less
1Proofpoint
1Insider Threat Management Server
Jun 17, 2026
Jun 27, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14...Show more
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.Show less
1Proofpoint
1Insider Threat Management Server
Jun 17, 2026
Jun 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitatio...Show more
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.Show less
1Proofpoint
1Insider Threat Management Server
Jun 17, 2026
Jun 27, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an atta...Show more
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.Show less
1Palantir
1Contour
Jun 17, 2026
Jun 27, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would other...Show more
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.Show less
1Dataease
1Dataease
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard cr...Show more
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Dataease
1Dataease
Jun 17, 2026
Jun 26, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has bee...Show more
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Codekop
1Codekop
Jun 17, 2026
Jun 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
1Hcltech
1Bigfix Webui Insights
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
1Stylemixthemes
1Masterstudy Lms
Jun 17, 2026
Jun 22, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of t...Show more
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.Show less
1Jenkins
1Team Concert
Jun 17, 2026
Jun 19, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
1Huawei
1Emui
Jun 17, 2026
Jun 19, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead to ads and other windows to display at any time.
1Easy Media Replace Project
1Easy Media Replace
Jun 17, 2026
Jun 19, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions.
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post.
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while th...Show more
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated. Show less
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.