VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 431 of 464
  • CVE-2024-8042LowSep 9, 2024
    risk 0.16cvss 2.4epss 0.00

    Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of a new user group. This could potentially lead to an empty user group being…

  • CVE-2023-2590LowMay 9, 2023
    risk 0.16cvss 3.5epss 0.00

    Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9.

  • CVE-2023-22489LowJan 13, 2023
    risk 0.16cvss 3.5epss 0.01

    Flarum is a discussion platform for websites. If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission or lock status. This…

  • CVE-2022-20529LowDec 16, 2022
    risk 0.16cvss 2.4epss 0.00

    In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege in wifi settings with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-25409LowJun 11, 2021
    risk 0.16cvss 2.4epss 0.00

    Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.

  • CVE-2021-1755LowApr 2, 2021
    risk 0.16cvss 2.4epss 0.00

    A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.

  • CVE-2018-21046LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. There is clipboard Data Exposure via the Emergency Dialer upon connecting a USB device. The Samsung ID is SVE-2018-12911 (November 2018).

  • CVE-2024-54020LowMay 28, 2025
    risk 0.15cvss 2.3epss 0.00

    A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds via crafted update requests.

  • CVE-2023-21450LowFeb 9, 2023
    risk 0.15cvss 2.3epss 0.00

    Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner's widget without authorization via gesture setting.

  • CVE-2022-20240LowDec 13, 2022
    risk 0.15cvss 2.3epss 0.00

    In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…

  • CVE-2022-20261LowAug 12, 2022
    risk 0.15cvss 2.3epss 0.00

    In LocationManager, there is a possible way to get location information due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-29480LowDec 15, 2020
    risk 0.15cvss 2.3epss 0.00

    An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for every created, modified, and deleted key.…

  • CVE-2026-52839LowJul 14, 2026
    risk 0.14cvss 3.3epss 0.00

    Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints…

  • CVE-2026-13235LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.

  • CVE-2026-11909LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.

  • CVE-2026-41498LowMay 8, 2026
    risk 0.14cvss 3.3epss 0.00

    Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team…

  • CVE-2026-34766LowApr 4, 2026
    risk 0.14cvss 3.3epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID against the filtered list that was…

  • CVE-2023-52275LowDec 31, 2023
    risk 0.14cvss 2.1epss 0.00

    Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3d/.privatealbum/.encryptfiles and guessing the correct image file extension.

  • CVE-2026-70483LowAug 4, 2026
    risk 0.13cvss 3.1epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any authenticated user who knew another user's…

  • CVE-2026-59226LowJul 9, 2026
    risk 0.13cvss 3.1epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automations, and check_model_access only enforced…