VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 185 of 475
  • CVE-2025-48524MedSep 4, 2025
    risk 0.36cvss 5.5epss 0.00

    In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-26445MedSep 4, 2025
    risk 0.36cvss 5.5epss 0.00

    In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-26437MedSep 4, 2025
    risk 0.36cvss 5.5epss 0.00

    In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2025-43977MedJul 21, 2025
    risk 0.36cvss 5.5epss 0.00

    The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster…

  • CVE-2025-43976MedJul 21, 2025
    risk 0.36cvss 5.5epss 0.00

    The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component.

  • CVE-2025-1055MedJun 11, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those…

  • CVE-2025-2589MedMar 21, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. The manipulation of the argument user_cookie leads to improper authorization. The exploit has been…

  • CVE-2025-24108MedJan 27, 2025
    risk 0.36cvss 5.5epss 0.00

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected user data.

  • CVE-2025-24096MedJan 27, 2025
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app may be able to access arbitrary files.

  • CVE-2025-22607MedJan 24, 2025
    risk 0.36cvss 5.5epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the details page for any GitHub / GitLab configuration on a Coolify instance by…

  • CVE-2018-9406MedJan 18, 2025
    risk 0.36cvss 5.5epss 0.00

    In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-25966MedDec 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through 5.1.4.

  • CVE-2024-37176MedJun 11, 2024
    risk 0.36cvss 5.5epss 0.00

    SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the confidentiality of data…

  • CVE-2024-32731MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.00

    SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the…

  • CVE-2023-52352MedApr 8, 2024
    risk 0.36cvss 5.5epss 0.00

    In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2024-26705MedApr 3, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: parisc: BTLB: Fix crash when setting up BTLB at CPU bringup When using hotplug and bringing up a 32-bit CPU, ask the firmware about the BTLB information to set up the static (block) TLB entries. For that…

  • CVE-2023-42896MedMar 28, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to modify protected parts of the file system.

  • CVE-2024-23230MedMar 8, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved file handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access sensitive user data.

  • CVE-2023-40113MedFeb 15, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40105MedFeb 15, 2024
    risk 0.36cvss 5.5epss 0.00

    In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.