← Back
CWE-862

8,705 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,705)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Delete Log
Jun 17, 2026
Nov 15, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.
1Jenkins
1Loader.io
Jun 17, 2026
Nov 15, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Jenkins
1Xp Dev
Jun 17, 2026
Nov 15, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.
1Jenkins
1Cloudbees Docker Hub/registry Notification
Jun 17, 2026
Nov 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.
1Webmaster Tools Verification Project
1Webmaster Tools Verification
Jun 17, 2026
Nov 14, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenticated users to disable arbitrary plugins
1Resmush.it
1Resmush.it Image Optimizer
Jun 17, 2026
Nov 14, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.
1Vmware
1Hyperic Server
Jun 17, 2026
Nov 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. N...Show more
A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
1Google
1Android
Jun 17, 2026
Nov 8, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed...Show more
In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235098883Show less
1Google
1Android
Jun 17, 2026
Nov 8, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execut...Show more
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-210065877Show less
1Google
1Android
Jun 17, 2026
Nov 8, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no...Show more
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-229793943Show less
1Searchwp
1Searchwp
Jun 17, 2026
Nov 8, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change.
1Weberge
1Wp Hide
Jun 17, 2026
Nov 7, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request
1Addify
1Product Stock Manager
Jun 17, 2026
Nov 7, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular...Show more
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary optionsShow less
1Coleds
1Simple Seo
Jun 17, 2026
Nov 3, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions.
1Oracle
1Restaurant Menu Food Ordering System Table Reservation
Jun 17, 2026
Nov 3, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks a...Show more
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal permissions to perform a wide variety of actions such as modifying the plugin's settings and modifying the ordering system preferences.Show less
1Wp Total Hacks Project
1Wp Total Hacks
Jun 17, 2026
Oct 31, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks again...Show more
The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.Show less
1Bricksbuilder
1Bricks
Jun 17, 2026
Oct 28, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with...Show more
The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.Show less
1Cloudflare
1Warp
Jun 17, 2026
Oct 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint.
1Cloudflare
1Warp Mobile Client
Jun 17, 2026
Oct 28, 2022
N/A· v4
8.5 HIGH· v3
N/A· v2
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lo...Show more
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform. Show less