← Back
CWE-862

8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,681)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Openshift Deployer
Jun 17, 2026
Apr 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connect...Show more
A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.Show less
1Jenkins
1Vmware Lab Manager Slaves
Jun 17, 2026
Apr 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an...Show more
A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.Show less
1Jenkins
1Audit To Database
Jun 17, 2026
Apr 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read permission to initiate a connection to a...Show more
A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.Show less
1Jenkins
1Ftp Publisher
Jun 17, 2026
Apr 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
1Robocode
1Robocode
Jun 17, 2026
Mar 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of a .openStream call w...Show more
Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of a .openStream call within java.net.URL.Show less
1Jenkins
1Fortify On Demand Uploader
Jun 17, 2026
Mar 28, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
1Jenkins
1Slack Notification
Jun 17, 2026
Mar 28, 2019
N/A· v4
7.5 HIGH· v3
3.5 LOW· v2
A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained thr...Show more
A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Medtronic
20Amplia Crt D Firmware
Carelink 2090 FirmwareCarelink Monitor Firmware+17 more
Jun 17, 2026
Mar 25, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Co...Show more
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement authentication or authorization. An attacker with adjacent short-range access to an affected product, in situations where the product’s radio is turned on, can inject, replay, modify, and/or intercept data within the telemetry communication. This communication protocol provides the ability to read and write memory values to affected implanted cardiac devices; therefore, an attacker could exploit this communication protocol to change memory in the implanted cardiac device.Show less
2Ovirt
Redhat
2Ovirt
Virtualization
Jun 17, 2026
Mar 25, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped...Show more
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.Show less
5Artifex
DebianFedoraproject+2 more
11Ansible Tower
Debian LinuxEnterprise Linux Desktop+8 more
Jun 17, 2026
Mar 25, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file syst...Show more
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.Show less
5Canonical
DebianGnu+2 more
6Bash
Debian LinuxHci Management Node+3 more
Jun 17, 2026
Mar 22, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
1Coturn Project
1Coturn
Nov 21, 2024
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback int...Show more
An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can provide administrator access to the TURN server configuration, which can lead to additional attacks. An attacker who can get access to the telnet port can gain administrator access to the TURN server.Show less
1Hidglobal
1Easylobby Solo
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized acti...Show more
EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized actions on the computer.Show less
1Hidglobal
1Easylobby Solo
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processes at will.
1Audiocodes
1420hd Ip Phone Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
1Gdata Software
1Total Security
Jun 17, 2026
Mar 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\gdwfp...Show more
gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\gdwfpcd device are not properly protected, leading to unintended impersonation or object creation.Show less
1Sap
5Advanced Business Application Programming Platform Kernel
Advanced Business Application Programming Platform Krnl32nucAdvanced Business Application Programming Platform Krnl32uc+2 more
Jun 17, 2026
Mar 12, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC...Show more
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.74, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, 7.74, 8.04, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, 7.74, 7.75, 8.04.Show less
1Joomla
1Joomla
Jun 17, 2026
Mar 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
1Jenkins
1Azure Vm Agents
Jun 17, 2026
Mar 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission to enumer...Show more
An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.Show less
1Jenkins
1Azure Vm Agents
Jun 17, 2026
Mar 8, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers with Overall/Read permission to attach a p...Show more
A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers with Overall/Read permission to attach a public IP address to an Azure VM agent.Show less