← Back
CWE-862

8,721 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,721)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In phoneEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
1Google
1Android
Jun 17, 2026
May 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed.
1Westerndigital
4My Cloud
My Cloud HomeMy Cloud Os 5+1 more
Jun 17, 2026
May 8, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 W...Show more
A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy and missing authentication requirement for private IPs, a remote attacker on the same network as the device could obtain device information by convincing a victim user to visit an attacker-controlled server and issue a cross-site request. This issue affects My Cloud OS 5 Mobile App: before 4.21.0; My Cloud Home Mobile App: before 4.21.0; ibi Mobile App: before 4.21.0; My Cloud OS 5 Web App: before 4.26.0-6126; My Cloud Home Web App: before 4.26.0-6126; ibi Web App: before 4.26.0-6126. Show less
1Apple
4Ipados
Iphone OsMacos+1 more
Jun 17, 2026
May 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. A shortcut may...Show more
The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. A shortcut may be able to use sensitive data with certain actions without prompting the user.Show less
2Djangoproject
Fedoraproject
2Django
Fedora
Jun 17, 2026
May 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileFie...Show more
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.Show less
1Gitlab
1Gitlab
Jun 17, 2026
May 3, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group membe...Show more
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even after being banned from the public group by the owner.Show less