← Back
CWE-862

8,705 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,705)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cloudflare
1Warp Mobile Client
Jun 17, 2026
Oct 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could b...Show more
Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action. Show less
1Cloudflare
1Warp Mobile Client
Jun 17, 2026
Oct 28, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  on the WARP iOS mobile client by enabling both "Disab...Show more
It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  on the WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. Such configuration caused the WARP client to disconnect and allowed the user to bypass restrictions and policies enforced by the Zero Trust platform.Show less
1Cloudflare
1Warp
Jun 17, 2026
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint caused the WARP Client to disconnect and...Show more
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint caused the WARP Client to disconnect and allowed bypassing administrative restrictions on a Zero Trust enrolled endpoint. Show less
1Forgerock
1Access Management
Jun 17, 2026
Oct 27, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.
1Nextcloud
2Nextcloud Enterprise Server
Nextcloud Server
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of informat...Show more
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.Show less
1Openfga
1Openfga
Jun 17, 2026
Oct 25, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/ope...Show more
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA service to the internet are vulnerable. Version 0.2.4 contains a patch for this issue.Show less
1Lemon8 Project
1Lemon8
Jun 17, 2026
Oct 24, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an...Show more
Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.Show less
1Aethon
1Tug Home Base Server
Jun 17, 2026
Oct 21, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
1Aethon
1Tug Home Base Server
Jun 17, 2026
Oct 21, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
1Aethon
1Tug Home Base Server
Jun 17, 2026
Oct 21, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
1Jenkins
1Compuware Strobe Measurement
Jun 17, 2026
Oct 19, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in...Show more
Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.Show less
1Jenkins
1Compuware Topaz For Total Test
Jun 17, 2026
Oct 19, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials st...Show more
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.Show less
1Jenkins
1Tuleap Git Branch Source
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers to trigger Tuleap projects whose configured repository matches the attacker-specified value.
1Jenkins
1Katalon
Jun 17, 2026
Oct 19, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified cre...Show more
Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Job Import
Jun 17, 2026
Oct 19, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Enalean
1Tuleap
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.99.228 and above, prior to 14.0.99.24, authorizations are not properly verified when updating the br...Show more
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.99.228 and above, prior to 14.0.99.24, authorizations are not properly verified when updating the branch prefix used by the GitLab repository integration. Authenticated users can change the branch prefix of any of the GitLab repository integration they can see vie the REST endpoint `PATCH /gitlab_repositories/{id}`. This action should be restricted to Git administrators. This issue is patched in Tuleap Community Edition 14.0.99.24 and Tuleap Enterprise Edition 14.0-3. There are no known workarounds.Show less
1Smackcoders
1Import All Pages, Post Types, Products, Orders, And Users As Xml & Csv
Jun 17, 2026
Oct 17, 2022
N/A· v4
4.2 MEDIUM· v3
N/A· v2
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related no...Show more
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonceShow less
1Miniorange
1Discord Integration
Jun 17, 2026
Oct 17, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for ex...Show more
The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for exampleShow less
1Otrs
1Otrs
Jun 17, 2026
Oct 17, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Article template contents with sensitive data could be accessed from agents without permissions.
1Google
1Android
Jun 17, 2026
Oct 14, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.