← Back
CWE-862

10,102 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (10,102)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Jan 4, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
1Google
1Android
Jun 17, 2026
Jan 4, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
1Google
1Android
Jun 17, 2026
Jan 4, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
1Google
1Android
Jun 17, 2026
Jan 4, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
1Google
1Android
Jun 17, 2026
Jan 4, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
1Google
1Android
Jun 17, 2026
Jan 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Jan 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Jan 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Jan 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
1Iubenda
1Iubenda Cookie Law Solution
Jun 17, 2026
Jan 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any...Show more
The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any authenticated users, such as subscriber can grant themselves any privileges, such as edit_plugins etcShow less
1Control Webpanel
1Webpanel
Jun 17, 2026
Dec 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&...Show more
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Dec 22, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This...Show more
When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.Show less
1Popup Manager Project
1Popup Manager
Jun 17, 2026
Dec 19, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them
1Genetechsolutions
1Pie Register
Jun 17, 2026
Dec 19, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their p...Show more
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)Show less
1Wpwax
1Directorist
Jun 17, 2026
Dec 19, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.
1Paxtechnology
1Paydroid
Jun 17, 2026
Dec 16, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in ADB daemon. The attacker must have physi...Show more
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in ADB daemon. The attacker must have physical USB access to the device in order to exploit this vulnerability.Show less
1Google
1Android
Jun 17, 2026
Dec 16, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User...Show more
In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-234475629References: Upstream kernelShow less
1Google
1Android
Jun 17, 2026
Dec 16, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege...Show more
In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246301667Show less
1Google
1Android
Jun 17, 2026
Dec 16, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privile...Show more
In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240301753Show less
1Google
1Android
Jun 17, 2026
Dec 16, 2022
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional executi...Show more
In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238745070Show less