← Back
CWE-862

9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (9,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sendgrid
1Sendgrid
Jun 17, 2026
Jul 30, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistic for a Wo...Show more
The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistic for a WordPress multi-site main site, in versions up to and including 1.11.8.Show less
1S Cms
1S Cms
Jun 17, 2026
Jul 30, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modification of a PHP file.
1Thimpress
1Learnpress
Jun 17, 2026
Jul 30, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
1Atlassian
3Jira Data Center
Jira Service DeskJira Service Management
Jun 17, 2026
Jul 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4...Show more
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting access to the Ehcache ports to only Data Center instances, fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service. [0] In Jira Data Center, Jira Core Data Center, and Jira Software Data Center versions prior to 7.13.1, the Ehcache object port can be randomly allocated. [1] In Jira Service Management Data Center versions prior to 3.16.1, the Ehcache object port can be randomly allocated.Show less
1Nextcloud
1Richdocuments
Jun 17, 2026
Jul 27, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these...Show more
Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP check. Whilst this does not result in gaining access to data that the user has not yet access to, it can result in a bypass of any enforced watermark on documents as described on the [Nextcloud Virtual Data Room](https://nextcloud.com/virtual-data-room/) website and [our documentation](https://portal.nextcloud.com/article/nextcloud-and-virtual-data-room-configuration-59.html). The Nextcloud Richdocuments releases 3.8.3 and 4.2.0 add an additional admin settings for an allowlist of IP addresses that can access the WOPI API. We recommend upgrading and configuring the allowlist to a list of Collabora servers. There is no known workaround. Note that this primarily results a bypass of any configured watermark or download protection using File Access Control. If you do not require or rely on these as a security feature no immediate action is required on your end.Show less
1Depstech
1Wifi Digital Microscope 3 Firmware
Jun 17, 2026
Jul 15, 2021
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment from the rightful device owner, because there is no way to reset to Factory Default settings.
1Google
1Android
Jun 17, 2026
Jul 14, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information disclosure from locked profiles with no additional execution privileges...Show more
In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information disclosure from locked profiles with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168802517References: N/AShow less
1Google
1Android
Jun 17, 2026
Jul 14, 2021
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names due to a missing permission check. This could lead to local information disclosure with no addition...Show more
In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-176496502Show less
1Google
1Android
Jun 17, 2026
Jul 14, 2021
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee...Show more
In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-176541017Show less
1Sap
1Customer Relationship Management
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
1Sap
1Netweaver Guided Procedures
Jun 17, 2026
Jul 14, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. T...Show more
SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. The impact of missing authorization could result to abuse of functionality restricted to a particular user group, and could allow unauthorized users to read, modify or delete restricted data.Show less
1Retty
1Retty
Jun 17, 2026
Jul 14, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 allows a remote attacker to lead a user to access an...Show more
Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.Show less
1Echobh
1Sharecare
Jun 17, 2026
Jul 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access page...Show more
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks such as SQL injection.Show less
1Halo
1Halo
Jun 17, 2026
Jul 12, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
File Deletion vulnerability in Halo 0.4.3 via delBackup.
1Gitlab
1Gitlab
Jun 17, 2026
Jul 7, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details
1Gu Global
1Gu
Jun 17, 2026
Jul 7, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
1Jenkins
1Requests
Jun 17, 2026
Jun 30, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.
1Craftcms
1Craft Cms
Jun 17, 2026
Jun 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to...Show more
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).Show less
1Mozilla
1Firefox
Jun 17, 2026
Jun 24, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode. This vulnerability affects Firefox for iO...Show more
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode. This vulnerability affects Firefox for iOS < 34.Show less
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.