← Back
CWE-862

8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,681)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to a local information disclosure of metada...Show more
In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to a local information disclosure of metadata about the biometrics of another user on the device with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128599663Show less
-
-
Nov 7, 2023
Sep 27, 2019
N/A· v4
N/A· v3
N/A· v2
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to local limited information disclosure wit...Show more
In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to local limited information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128599864Show less
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper image with no additional execution privileges needed. User interaction...Show more
In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper image with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-30770233Show less
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local escalation of privilege with User execution privileges needed. User in...Show more
In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-36885811Show less
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...Show more
In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73136824Show less
3Debian
FedoraprojectMediawiki
3Debian Linux
FedoraMediawiki
Jun 17, 2026
Sep 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
1Jenkins
1Project Inheritance
Jun 17, 2026
Sep 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers with Overall/Read permission to trigger project generation from templates.
1Gitlab
1Gitlab
Jun 17, 2026
Sep 16, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.
4Canonical
LinuxOpensuse+1 more
4Enterprise Linux
LeapLinux Kernel+1 more
Jun 17, 2026
Sep 13, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transa...Show more
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then accesses vector registers. At some point, the vector registers will be corrupted with the values from a different local Linux process because of a missing arch/powerpc/kernel/process.c check.Show less
4Canonical
DebianDino+1 more
4Debian Linux
DinoFedora+1 more
Jun 17, 2026
Sep 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
1Atlassian
1Jira Server
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.
1Ttlock
1Ttlock
Jun 17, 2026
Sep 10, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is unavailable.
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.
1Youphptube
1Youphptube
Jun 17, 2026
Sep 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.
1Linuxfoundation
1Harbor
Jun 17, 2026
Sep 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. F...Show more
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.Show less
1Totaljs
1Total.js Cms
Jun 17, 2026
Sep 5, 2019
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag cont...Show more
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>Show less
1Totaljs
1Total.js Cms
Jun 17, 2026
Sep 5, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only...Show more
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only for the front-end resource path, not for API requests. This leads to vertical and horizontal privilege escalation.Show less
1Wpbrigade
1Loginpress
Jun 17, 2026
Sep 3, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
2Androvideo
Geovision
3Gv Vd8700 Firmware
Gv Vr360 FirmwareVd 1 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.