← Back
CWE-862

8,702 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,702)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Html2wp Project
1Html2wp
Jun 17, 2026
Jun 27, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file
1Watchful
1Xcloner
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset t...Show more
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.Show less
1Illumina
1Local Run Manager
Jun 17, 2026
Jun 24, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.
1Jenkins
1Vrealize Orchestrator
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.
1Jenkins
1Threadfix
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
1Jenkins
1Beaker Builder
Jun 17, 2026
Jun 23, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
1Jenkins
1Jianliao Notification
Jun 17, 2026
Jun 23, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL.
1Jenkins
1Easyqa
Jun 17, 2026
Jun 23, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
1Jenkins
1Convertigo Mobile Platform
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
1Shinasys
3Sihas Acm 300 Firmware
Sihas Gcm 300 FirmwareSihas Sgw 300 Firmware
Jun 17, 2026
Jun 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
1Frappe
1Erpnext
Jun 17, 2026
Jun 22, 2022
N/A· v4
N/A· v3
5.5 MEDIUM· v2
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, i...Show more
In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.Show less
1Discourse
1Discourse Chat
Jun 17, 2026
Jun 21, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel they do not have acces...Show more
discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel they do not have access to can view that message using the chat message lookup endpoint, primarily affecting direct message channels. There are no known workarounds for this issue, and users are advised to update the plugin.Show less
1Mahara
1Mahara
Jun 17, 2026
Jun 20, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
1Xos Shop
1Xos Shop System
Jun 17, 2026
Jun 16, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/categories.php
1Xos Shop
1Xos Shop System
Jun 17, 2026
Jun 16, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/manufacturers.php.
1Cisco
1Appdynamics Controller
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative conso...Show more
A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to access. This vulnerability is due to improper authorization checking for HTTP requests that are submitted to the affected web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected instance of AppDynamics Controller. A successful exploit could allow the attacker to access the login page for an administrative console. AppDynamics has released software updates that address this vulnerability.Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclosure about enabled notification listeners with User execution privileges...Show more
In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclosure about enabled notification listeners with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-220737634Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no a...Show more
In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-171495100Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User in...Show more
In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-212695058Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges ne...Show more
In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222348453References: N/AShow less