← Back
CWE-862

8,702 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,702)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User inte...Show more
In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-206987222References: N/AShow less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to loca...Show more
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-210469972Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User ex...Show more
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-206986392Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed....Show more
In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-206807679Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User exe...Show more
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-203431023Show less
1Sap
1Adaptive Server Enterprise
Jun 17, 2026
Jun 14, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
1Couchbase
1Couchbase Server
Jun 17, 2026
Jun 13, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality.
1Filr Project
1Filr
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected with a nonce, howev...Show more
The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected with a nonce, however the nonce is leaked on the dashboard. This could allow them to upload arbitrary HTML files as well as delete all files or arbitrary ones.Show less
1Memberhero
1Member Hero
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments...Show more
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.Show less
1Likebtn
1Like Button Rating
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body
1Enqueue Anything Project
1Enqueue Anything
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low priv...Show more
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low privilege users such as subscriber could delete arbitrary assets, as well as put arbitrary posts in the trash.Show less
1Enalean
1Tuleap
Jun 17, 2026
Jun 9, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report render...Show more
Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.Show less
1Files Download Delay Project
1Files Download Delay
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.
1Samsung
1Smartthings
Jun 17, 2026
Jun 7, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.
1Samsung
1My Files
Jun 17, 2026
Jun 7, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application.
1Google
1Android
Jun 17, 2026
Jun 6, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...Show more
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511058; Issue ID: ALPS06511058.Show less
1Google
1Android
Jun 17, 2026
Jun 6, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitati...Show more
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06511030; Issue ID: ALPS06511030.Show less
1Content Mask Project
1Content Mask
Jun 17, 2026
May 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result,...Show more
The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as subscriber could modify arbitrary blog optionsShow less
1Ibm
2Elastic Storage System
Spectrum Scale
Jun 17, 2026
May 24, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 19160...Show more
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600.Show less