← Back
CWE-862

9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (9,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Sep 8, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to access notes from the lock screen.
1Hashicorp
1Consul
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
1Comprotech
4Ip570 Firmware
Ip60 FirmwareIp70 Firmware+1 more
Jun 17, 2026
Sep 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.
1Comprotech
4Ip570 Firmware
Ip60 FirmwareIp70 Firmware+1 more
Jun 17, 2026
Sep 1, 2021
N/A· v4
8.1 HIGH· v3
8.5 HIGH· v2
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.
1Unit4
1Mik.starlight
Jun 17, 2026
Aug 31, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
1Primekey
1Ejbca
Jun 17, 2026
Aug 25, 2021
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as...Show more
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.Show less
1Apple
3Ipados
Iphone OsMacos
Jun 17, 2026
Aug 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installed by an app without user permission.
1Rconfig
1Rconfig
Jun 17, 2026
Aug 20, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a crafted file.
1Rconfig
1Rconfig
Jun 17, 2026
Aug 20, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via a crafted ZIP file.
1Rconfig
1Rconfig
Jun 17, 2026
Aug 20, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying...Show more
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext parameter and delete all the files with that extension in that path.Show less
1Google
1Android
Jun 17, 2026
Aug 18, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction...Show more
In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336692.Show less
1Google
1Android
Jun 17, 2026
Aug 17, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no add...Show more
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-185126149Show less
1Google
1Android
Jun 17, 2026
Aug 17, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no addition...Show more
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185235454Show less
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
1Dcce
1Mac1100 Plc Firmware
Jun 17, 2026
Aug 13, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.
1Dcce
1Mac1100 Plc Firmware
Jun 17, 2026
Aug 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted packet.
1Amentotech
1Workreap
Jun 17, 2026
Aug 9, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a lo...Show more
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.Show less
1Amentotech
1Workreap
Jun 17, 2026
Aug 9, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logge...Show more
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.Show less
1Totolink
1A720r Firmware
Jun 17, 2026
Aug 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.
1Golang
1Go
Jun 17, 2026
Aug 2, 2021
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers.