← Back
CWE-862

8,702 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,702)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sick
1Ftmg Firmware
Jun 17, 2026
Jul 19, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the...Show more
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.Show less
1Wbcomdesigns
1Buddypress Group Reviews
Jun 17, 2026
Jul 18, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions rel...Show more
The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.Show less
1Google
1Android
Jun 17, 2026
Jul 13, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional executio...Show more
In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213457638Show less
1Sap
2S/4hana
Sapscore
Jun 17, 2026
Jul 12, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenti...Show more
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.Show less
1Sap
1Enterprise Extension Defense Forces & Public Security
Jun 17, 2026
Jul 12, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The application SAP Enterprise Extension Defense Forces & Public Security - versions 605, 606, 616,617,618, 802, 803, 804, 805, 806, does not perform necessary authorization checks for an authenticated user over the netw...Show more
The application SAP Enterprise Extension Defense Forces & Public Security - versions 605, 606, 616,617,618, 802, 803, 804, 805, 806, does not perform necessary authorization checks for an authenticated user over the network, resulting in escalation of privileges leading to a limited impact on confidentiality.Show less
1Redhat
1Keycloak
Jun 17, 2026
Jul 8, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the clie...Show more
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.Show less
1Google
1Android
Jun 17, 2026
Jul 6, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...Show more
In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06713894; Issue ID: ALPS06713894.Show less
1Google
1Android
Jun 17, 2026
Jul 6, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...Show more
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044717.Show less
1Google
1Android
Jun 17, 2026
Jul 6, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne...Show more
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044708.Show less
1Jenkins
1Failed Job Deactivator
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP endpoints, allowing attackers with Overall/Read permission to disable jobs.
1Jenkins
1Xpath Configuration Viewer
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to create and delete XPath expressions.
1Jenkins
1Xpath Configuration Viewer
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to access the XPath Configuration Viewer page.
1Jenkins
1Rqm
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Jenkins
1Deployment Dashboard
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using att...Show more
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.Show less
1Jenkins
1Deployment Dashboard
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Jenkins
1Recipe
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.
1Jenkins
1Xebialabs Xl Release
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs ob...Show more
Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Xebialabs Xl Release
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Armemberplugin
1Armember
Jun 17, 2026
Jun 27, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to c...Show more
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their usernameShow less
1Html2wp Project
1Html2wp
Jun 17, 2026
Jun 27, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on...Show more
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote serverShow less