CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,489)
page 183 of 475| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-4175 | Med | 0.38 | 5.9 | 0.02 | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle… | ||
| CVE-2020-4413 | Med | 0.38 | 5.9 | 0.01 | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle… | ||
| CVE-2019-7272 | Med | 0.38 | 5.3 | 0.10 | Jul 1, 2019 | Optergy Proton/Enterprise devices allow Username Disclosure. | ||
| CVE-2026-19017 | Med | 0.37 | 6.8 | 0.00 | Aug 7, 2026 | Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul… | ||
| CVE-2026-44409 | Med | 0.37 | 5.7 | 0.00 | May 22, 2026 | There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure. | ||
| CVE-2025-65089 | Med | 0.37 | 6.8 | 0.00 | Nov 19, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched… | ||
| CVE-2025-25244 | Med | 0.37 | 5.7 | 0.00 | Mar 11, 2025 | SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding… | ||
| CVE-2024-0235 | Med | 0.37 | 5.3 | 0.38 | Jan 16, 2024 | The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog | ||
| CVE-2023-47870 | Med | 0.37 | 5.7 | 0.00 | Nov 30, 2023 | Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a… | ||
| CVE-2023-26510 | Med | 0.37 | 5.7 | 0.01 | Mar 5, 2023 | Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this… | ||
| CVE-2023-22488 | Med | 0.37 | 6.8 | 0.00 | Jan 12, 2023 | Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification… | ||
| CVE-2022-39960 | Med | 0.37 | 5.3 | 0.26 | Sep 17, 2022 | The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/… | ||
| CVE-2022-34212 | Med | 0.37 | 5.7 | 0.01 | Jun 23, 2022 | A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL. | ||
| CVE-2021-25011 | Med | 0.37 | 5.7 | 0.00 | Feb 28, 2022 | The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings. | ||
| CVE-2020-13938 | Med | 0.37 | 5.5 | 0.12 | Jun 10, 2021 | Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows | ||
| CVE-2019-16097 | Med | 0.37 | 6.5 | 0.22 | Sep 8, 2019 | core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without… | ||
| CVE-2026-61936 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-15248 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2026 | The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users. | ||
| CVE-2026-18201 | Med | 0.36 | 5.5 | 0.00 | Jul 29, 2026 | Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions… | ||
| CVE-2026-44918 | Med | 0.36 | 5.5 | 0.00 | Jul 10, 2026 | OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. |
- risk 0.38cvss 5.9epss 0.02
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…
- risk 0.38cvss 5.9epss 0.01
IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…
- risk 0.38cvss 5.3epss 0.10
Optergy Proton/Enterprise devices allow Username Disclosure.
- risk 0.37cvss 6.8epss 0.00
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul…
- risk 0.37cvss 5.7epss 0.00
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.
- risk 0.37cvss 6.8epss 0.00
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched…
- risk 0.37cvss 5.7epss 0.00
SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding…
- risk 0.37cvss 5.3epss 0.38
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
- risk 0.37cvss 5.7epss 0.00
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a…
- risk 0.37cvss 5.7epss 0.01
Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this…
- risk 0.37cvss 6.8epss 0.00
Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification…
- risk 0.37cvss 5.3epss 0.26
The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/…
- risk 0.37cvss 5.7epss 0.01
A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.
- risk 0.37cvss 5.7epss 0.00
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.
- risk 0.37cvss 5.5epss 0.12
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
- risk 0.37cvss 6.5epss 0.22
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without…
- risk 0.36cvss 5.5epss 0.00
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.5epss 0.00
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.
- risk 0.36cvss 5.5epss 0.00
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions…
- risk 0.36cvss 5.5epss 0.00
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.