← Back
CWE-862

10,076 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (10,076)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Palantir
1Contour
Jun 17, 2026
Jun 27, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would other...Show more
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.Show less
1Dataease
1Dataease
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard cr...Show more
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Dataease
1Dataease
Jun 17, 2026
Jun 26, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has bee...Show more
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Codekop
1Codekop
Jun 17, 2026
Jun 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
1Hcltech
1Bigfix Webui Insights
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
1Stylemixthemes
1Masterstudy Lms
Jun 17, 2026
Jun 22, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of t...Show more
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.Show less
1Jenkins
1Team Concert
Jun 17, 2026
Jun 19, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
1Huawei
1Emui
Jun 17, 2026
Jun 19, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead to ads and other windows to display at any time.
1Easy Media Replace Project
1Easy Media Replace
Jun 17, 2026
Jun 19, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions.
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post.
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while th...Show more
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated. Show less
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.
1Mattermost
1Mattermost
Jun 17, 2026
Jun 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
1Huawei
1Harmonyos
Jun 17, 2026
Jun 16, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions.
1Google
1Android
Jun 17, 2026
Jun 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed....Show more
In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-262244249Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with...Show more
In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-270050064Show less
1Google
1Android
Jun 17, 2026
Jun 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no...Show more
In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-270050191Show less
1Jenkins
1Digital.ai App Management Publisher
Jun 17, 2026
Jun 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenk...Show more
A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.Show less