CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
9,518 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 1 of 191
- CVE-2005-3623MEDIUMCVSS v2 5.0EG 5.02005-12-31
nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.
- CVE-2006-4483HIGHCVSS v2 9.3EG 9.32006-08-31
The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, po…
- CVE-2009-2282MEDIUMCVSS v2 4.6EG 4.62009-07-01
The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local cont…
- CVE-2009-3168HIGHCVSS 7.2EG 7.22009-09-11
Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct…
- CVE-2009-3781HIGHCVSS v2 7.5EG 7.52009-10-26
The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vecto…
- CVE-2011-4183CRITICALCVSS 6.5EG 9.82018-06-13
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.
- CVE-2012-0055HIGHCVSS 7.8EG 7.82020-02-19
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.
- CVE-2012-4245MEDIUMCVSS v2 6.8EG 6.82012-08-31
The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.
- CVE-2012-6614HIGHCVSS 7.2EG 7.22020-02-19
D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password.
- CVE-2013-10072MEDIUMCVSS 6.5EG 6.52025-10-30
Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing …
- CVE-2013-3703HIGHCVSS 8.8EG 8.82018-06-08
The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data.
- CVE-2013-3960CRITICALCVSS 9.9EG 9.92020-01-24
Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass
- CVE-2013-4226MEDIUMCVSS 6.5EG 6.52020-02-18
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive i…
- CVE-2015-0571HIGHCVSS 7.8EG 7.82016-05-09
The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify authorization for private SET IOCTL calls, which allows at…
- CVE-2015-10140HIGHCVSS 8.8EG 8.82025-07-22
The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.
- CVE-2015-10143CRITICALCVSS 9.8EG 9.82025-07-25
The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the *_ajax_save_options() function in all versions up to 1.4.4 (exclusive). This…
- CVE-2015-20067HIGHCVSS 7.5EG 7.52021-11-01
The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress
- CVE-2015-8840HIGHCVSS 8.8EG 8.82016-04-08
The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via request…
- CVE-2016-11036CRITICALCVSS 9.8EG 9.82020-04-07
An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).
- CVE-2017-0554HIGHCVSS 7.8EG 7.82017-04-07
An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels. This issue is rated as Moderate because it could be used to gain access …
- CVE-2017-0896MEDIUMCVSS 6.5EG 6.52017-06-02
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization e…
- CVE-2017-1000056CRITICALCVSS 9.8EG 9.82017-07-17
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.
- CVE-2017-1000086HIGHCVSS 8.0EG 8.02017-10-05
The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download backups, and also delete all previous backups via log rotation.…
- CVE-2017-1000105MEDIUMCVSS 5.3EG 5.32017-10-05
The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.
- CVE-2017-1000243MEDIUMCVSS 4.3EG 4.32017-11-01
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
- CVE-2017-1000388MEDIUMCVSS 4.3EG 4.32018-01-26
Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modify this data.
- CVE-2017-1000390MEDIUMCVSS 4.3EG 4.32018-01-26
Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build.
- CVE-2017-1000400MEDIUMCVSS 4.3EG 4.32018-01-26
The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. d…
- CVE-2017-1002006HIGHCVSS 7.5EG 7.52017-09-14
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
- CVE-2017-1002007HIGHCVSS 7.5EG 7.52017-09-14
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.
- CVE-2017-1002151HIGHCVSS 7.5EG 7.52017-09-14
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
- CVE-2017-10846HIGHCVSS 7.5EG 7.52017-09-15
Wi-Fi STATION L-02F Software version V10b and earlier allows remote attackers to bypass access restrictions to obtain information on device settings via unspecified vectors.
- CVE-2017-11042HIGHCVSS 7.8EG 7.82017-12-05
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, ImsService and the IQtiImsExt AIDL APIs are not subject to access control.
- CVE-2017-11135HIGHCVSS 7.5EG 7.52017-08-01
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The logout mechanism does not check for authorization. Therefore, an attacker only needs to know the dev…
- CVE-2017-12084HIGHCVSS 6.6EG 8.02017-11-07
A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent backdoor. An attacker…
- CVE-2017-12582CRITICALCVSS 9.8EG 9.82017-08-18
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can a…
- CVE-2017-13209HIGHCVSS 7.8EG 7.82018-01-12
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This coul…
- CVE-2017-13247HIGHCVSS 7.8EG 7.82018-02-12
In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileges with user execution privileges needed. User interaction is not needed for exploitation.…
- CVE-2017-13314HIGHCVSS 7.8EG 7.82024-11-15
In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when th…
- CVE-2017-13316HIGHCVSS 7.8EG 8.42024-11-27
In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2017-15680MEDIUMCVSS 6.5EG 6.52020-11-27
In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.
- CVE-2017-17433LOWCVSS 3.7EG 3.72017-12-06
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows …
- CVE-2017-17448HIGHCVSS 7.8EG 7.82017-12-07
net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for new, get, and del operations, which allows local users to bypass intended access restrictions because the nfnl_cthelper…
- CVE-2017-17450HIGHCVSS 7.8EG 7.82017-12-07
net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for add_callback and remove_callback operations, which allows local users to bypass intended access restrictions because the xt_osf_fin…
- CVE-2017-17665HIGHCVSS 8.8EG 8.82017-12-13
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control bypass because the set of environments to which a machine is scoped may include environmen…
- CVE-2017-17693MEDIUMCVSS 4.3EG 4.32017-12-15
Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback.
- CVE-2017-17707HIGHCVSS 8.1EG 8.12018-07-31
Due to missing authorization checks, any authenticated user is able to list, upload, or delete attachments to password safe entries in Pleasant Password Server before 7.8.3. To perform those actions on an entry, the user needs to know the …
- CVE-2017-17807LOWCVSS 3.3EG 3.32017-12-20
The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing a local user to use a sequence of crafte…
- CVE-2017-18035MEDIUMCVSS 4.3EG 4.32018-02-02
The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular…
- CVE-2017-18101MEDIUMCVSS 6.5EG 6.52018-04-10
Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow re…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →