← Back
CWE-862

8,698 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,698)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Cloudbees Aws Credentials
Jun 17, 2026
Mar 15, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.
1Thememove
1Insight Core
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it...Show more
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before outputting it in the response. As a result, it could allow users with a role as low as Subscriber to perform PHP Object Injection, as well as Stored Cross-Site Scripting attacksShow less
1Moodle
1Moodle
Jun 17, 2026
Mar 11, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affecte...Show more
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.Show less
1Moodle
1Moodle
Jun 17, 2026
Mar 11, 2022
N/A· v4
4.3 MEDIUM· v3
2.6 LOW· v2
Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected.
1Saleor
1Saleor
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.
1Gogs
1Gogs
Jun 17, 2026
Mar 11, 2022
N/A· v4
9.1 CRITICAL· v3
5.8 MEDIUM· v2
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is abl...Show more
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful exploitation an attacker requires knowledge of the sharing link. It is recommended that users upgrade their Nextcloud Server to 20.0.14, 21.0.6 or 22.2.1. Users unable to upgrade should disable the Nextcloud Text application in the application settings.Show less
1Sap
1Financial Consolidation
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message.
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
1Sap
1Netweaver Application Server Abap
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available wi...Show more
Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP system even if he/she isn't authorized for that transaction. A successful exploitation could expose information and in worst case manipulate data before the start screen is executed, resulting in limited impact on confidentiality and integrity of the application.Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219083; Issue ID: ALPS06219083.Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...Show more
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219097; Issue ID: ALPS06219097.Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more
In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05954679; Issue ID: ALPS05954679.Show less
1Gitea
1Gitea
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Mar 8, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permi...Show more
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted access to the groupfolder but not specific subfolders. Due to a lacking permission check in affected versions, a user could still access these subfolders by copying the groupfolder to another location. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. Users unable to upgrade should disable the "groupfolders" application in the admin settings.Show less
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Mar 8, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enum...Show more
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the instance, even when user listings where disabled. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. There are no known workarounds.Show less
1Salesagility
1Suitecrm
Jun 17, 2026
Mar 7, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
1Salesagility
1Suitecrm
Jun 17, 2026
Mar 7, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
1Rednao
1Smart Forms
Jun 17, 2026
Mar 7, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, whic...Show more
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.Show less
1W3eden
1Download Manager
Jun 17, 2026
Mar 7, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information dis...Show more
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).Show less