← Back
CWE-862

9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (9,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Drupal
1Authenticated User Page Caching
Nov 21, 2024
Feb 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to...Show more
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.Show less
1Google
1Android
Jun 17, 2026
Feb 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.7 MEDIUM· v2
In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app...Show more
In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluetooth connection, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145130871Show less
1Sap
2Erp
S/4 Hana
Jun 17, 2026
Feb 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorizatio...Show more
VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing Authorization Check.Show less
1Sap
1Host Agent
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive responses that may contain data read with user...Show more
SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive responses that may contain data read with user root privileges e.g. size of any directory, system hardware and OS details, leading to Missing Authorization Check vulnerability.Show less
6Debian
FedoraprojectGoogle+3 more
8Backports Sle
ChromeDebian Linux+5 more
Jun 17, 2026
Feb 11, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
1Bludit
1Bludit
Jun 17, 2026
Feb 7, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.
1Revmakx
1Infinitewp Client
Jun 17, 2026
Feb 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.
1Gitlab
1Gitlab
Jun 17, 2026
Feb 5, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
1Prototypejs
1Prototype
Jun 17, 2026
Feb 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.
1Kronos
1Web Time And Attendance
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrativ...Show more
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within the application via the delegate, delegateRole, and delegatorUserId parameters.Show less
1Apereo
1Opencast
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of u...Show more
Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of users to protect media. This leads to users unknowingly handing out public access to events without their knowledge. The problem has been addressed in Opencast 7.6 and 8.1 where the OAI-PMH endpoint is configured to require users with `ROLE_ADMIN` by default. In addition to this, Opencast 9 removes the OAI-PMH publication from the default workflow, making the publication a conscious decision users have to make by updating their workflows.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.
1Easytimestudio
1Easy File Manager
Nov 21, 2024
Jan 24, 2020
N/A· v4
9.9 CRITICAL· v3
8.7 HIGH· v2
Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass
1Gallagher
1Command Centre
Jun 17, 2026
Jan 17, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an authenticated user connecting to OP...Show more
In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an authenticated user connecting to OPCUA can view all data that would be replicated in a multi-server setup without privilege checks being applied.Show less
1Jenkins
1Health Advisor By Cloudbees
Jun 17, 2026
Jan 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.
1Jenkins
1Amazon Ec2
Jun 17, 2026
Jan 15, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials ID...Show more
A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.Show less
1Sap
1Leasing
Jun 17, 2026
Jan 14, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and 6.17).
1Webfactoryltd
1Minimal Coming Soon & Maintenance Mode
Jun 17, 2026
Jan 9, 2020
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidenti...Show more
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).Show less
2Canonical
Mozilla
4Firefox
Firefox EsrThunderbird+1 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of exist...Show more
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.Show less
1Business Alliance Financial Circle Project
1Business Alliance Financial Circle
Nov 21, 2024
Dec 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is...Show more
The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is public (by default) and does not check the caller's identity.Show less