← Back
CWE-862

9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (9,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
2Jira Data Center
Jira Server
Jun 17, 2026
Mar 17, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access t...Show more
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.Show less
1Jfrog
1Artifactory
Jun 17, 2026
Mar 16, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."
1Easyappointments
1Easy!appointments
Nov 21, 2024
Mar 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
1Sap
1Disclosure Management
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration accounts by a user with no roles, leading to Missing Authorization Che...Show more
SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration accounts by a user with no roles, leading to Missing Authorization Check.Show less
1Sap
2Treasury And Risk Management (ea Finserv)
Treasury And Risk Management (s4core)
Jun 17, 2026
Mar 10, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it shoul...Show more
The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check.Show less
1Sap
1Erp
Jun 17, 2026
Mar 10, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have a...Show more
The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker without an authorization group can maintain any company certificate, leading to Missing Authorization Check.Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In setBluetoothTethering of PanService.java, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege to activate tethering with no additional execution pr...Show more
In setBluetoothTethering of PanService.java, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege to activate tethering with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-134487438Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local escalation of privilege by creating fake system notifications with no additional execution privileges...Show more
In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local escalation of privilege by creating fake system notifications with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143339775Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In WifiNetworkSuggestionsManager of WifiNetworkSuggestionsManager.java, there is a possible permission revocation due to a missing permission check. This could lead to local escalation of privilege with no additional exe...Show more
In WifiNetworkSuggestionsManager of WifiNetworkSuggestionsManager.java, there is a possible permission revocation due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146642727Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In setMasterMute of AudioService.java, there is a missing permission check. This could lead to local silencing of audio with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...Show more
In setMasterMute of AudioService.java, there is a missing permission check. This could lead to local silencing of audio with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141622311Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User inte...Show more
In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-140622024Show less
1Themerex
63Addons
Aldo Gutenberg Wordpress Blog ThemeAmuli+60 more
Jun 17, 2026
Mar 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-...Show more
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.Show less
1Jenkins
1P4
Jun 17, 2026
Mar 9, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to trigger builds.
1Metagauss
1Registrationmagic
Jun 17, 2026
Mar 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and settings via class_rm_form_controller.php r...Show more
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and settings via class_rm_form_controller.php rm_form_export.Show less
1Metagauss
1Registrationmagic
Jun 17, 2026
Mar 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php,...Show more
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.Show less
1Metagauss
1Registrationmagic
Jun 17, 2026
Mar 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php...Show more
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.Show less
1Metagauss
1Registrationmagic
Jun 17, 2026
Mar 6, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php send_email_user_view.
1Seling
1Visual Access Manager
Jun 17, 2026
Feb 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user identity and authorization.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Nov 21, 2024
Feb 19, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.
1Dlink
1Dsr 250n Firmware
Nov 21, 2024
Feb 19, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password.