← Back
CWE-862

8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,681)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Activity Streams
Nov 21, 2024
Jan 29, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched pa...Show more
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have access to, although they will not receive notifications for the issue, via missing permission checks.Show less
1Jenkins
1Jenkins
Nov 21, 2024
Jan 26, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has n...Show more
The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only lists upstream and downstream projects that the current user has access to.Show less
1Jenkins
1Multijob
Nov 21, 2024
Jan 26, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build.
1Jenkins
1Dependency Graph Viewer
Nov 21, 2024
Jan 26, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modify this data.
1Jenkins
1Pipeline Nodes And Processes
Nov 21, 2024
Jan 23, 2018
N/A· v4
4.8 MEDIUM· v3
4.9 MEDIUM· v2
On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those...Show more
On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier.Show less
1Asus
1Asuswrt
Jun 17, 2026
Jan 22, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to...Show more
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.Show less
1Cisco
1Nx Os
Nov 21, 2024
Jan 18, 2018
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A vulnerability in the network-operator user role implementation for Cisco NX-OS System Software could allow an authenticated, local attacker to improperly delete valid user accounts. The network-operator role should not...Show more
A vulnerability in the network-operator user role implementation for Cisco NX-OS System Software could allow an authenticated, local attacker to improperly delete valid user accounts. The network-operator role should not be able to delete other configured users on the device. The vulnerability is due to a lack of proper role-based access control (RBAC) checks for the actions that a user with the network-operator role is allowed to perform. An attacker could exploit this vulnerability by authenticating to the device with user credentials that give that user the network-operator role. Successful exploitation could allow the attacker to impact the integrity of the device by deleting configured user credentials. The attacker would need valid user credentials for the device. This vulnerability affects the following Cisco products running Cisco NX-OS System Software: Nexus 3000 Series Switches, Nexus 3600 Platform Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvg21120.Show less
1Google
1Android
Nov 21, 2024
Jan 12, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own...Show more
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217907.Show less
1Discuz
1Discuzx
Nov 21, 2024
Jan 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.
1Linux
1Linux Kernel
May 13, 2026
Dec 20, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing a local user to use a...Show more
The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing a local user to use a sequence of crafted system calls to add keys to a keyring with only Search permission (not Write permission) to that keyring, related to construct_get_dest_keyring() in security/keys/request_key.c.Show less
1Techno Portfolio Management Panel Project
1Techno Portfolio Management Panel
May 13, 2026
Dec 15, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback.
1Octopus
1Octopus Deploy
May 13, 2026
Dec 13, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control bypass because the set of environments to which a machine is scoped may...Show more
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control bypass because the set of environments to which a machine is scoped may include environments in which the user lacks access.Show less
1Linux
1Linux Kernel
May 13, 2026
Dec 7, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for add_callback and remove_callback operations, which allows local users to bypass intended access restrictions bec...Show more
net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for add_callback and remove_callback operations, which allows local users to bypass intended access restrictions because the xt_osf_fingers data structure is shared across all net namespaces.Show less
1Linux
1Linux Kernel
May 13, 2026
Dec 7, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for new, get, and del operations, which allows local users to bypass intended access restrictions becaus...Show more
net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for new, get, and del operations, which allows local users to bypass intended access restrictions because the nfnl_cthelper_list data structure is shared across all net namespaces.Show less
2Debian
Samba
2Debian Linux
Rsync
May 13, 2026
Dec 6, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data struc...Show more
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions.Show less
1Google
1Android
May 13, 2026
Dec 5, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, ImsService and the IQtiImsExt AIDL APIs are not subject to access control.
1Meetcircle
1Circle With Disney Firmware
May 13, 2026
Nov 7, 2017
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent ba...Show more
A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent backdoor. An attacker can send an API call to enable the SSH server.Show less
1Jenkins
1Favorite Plugin
May 13, 2026
Nov 1, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
1Jenkins
1Blue Ocean
May 13, 2026
Oct 5, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.
1Jenkins
1Periodic Backup
May 13, 2026
Oct 5, 2017
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download backups, and also delete all previous backup...Show more
The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download backups, and also delete all previous backups via log rotation. Additionally, the plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks.Show less