VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 52 of 464
  • CVE-2025-31685CriMar 31, 2025
    risk 0.52cvss 9.1epss 0.00

    Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.

  • CVE-2024-55879CriDec 12, 2024
    risk 0.52cvss 9.1epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality,…

  • CVE-2024-4163HigApr 26, 2024
    risk 0.52cvss 8.0epss 0.00

    The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovered that the process was running under root privileges. This allowed the attacker to read, write, and modify any file in the operating system by utilizing the…

  • CVE-2023-36144HigJun 30, 2023
    risk 0.52cvss 7.5epss 0.37

    An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.

  • CVE-2022-0871CriMar 11, 2022
    risk 0.52cvss 9.1epss 0.01

    Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

  • CVE-2021-24914HigDec 6, 2021
    risk 0.52cvss 8.0epss 0.01

    The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-privileged users (including simple subscribers) to change the…

  • CVE-2021-21689CriNov 4, 2021
    risk 0.52cvss 9.1epss 0.01

    FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2021-21685CriNov 4, 2021
    risk 0.52cvss 9.1epss 0.01

    Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs.

  • CVE-2021-38486HigOct 19, 2021
    risk 0.52cvss 8.0epss 0.01

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have full control over the product and execute code within the…

  • CVE-2020-8495HigJan 30, 2020
    risk 0.52cvss 7.5epss 0.03

    In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within the application via the delegate,…

  • CVE-2019-10849HigMay 23, 2019
    risk 0.52cvss 7.5epss 0.09

    Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.

  • CVE-2017-12084HigNov 7, 2017
    risk 0.52cvss 8.0epss 0.01

    A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent backdoor. An attacker can send an API call to enable the SSH…

  • CVE-2017-1000086HigOct 5, 2017
    risk 0.52cvss 8.0epss 0.01

    The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download backups, and also delete all previous backups via log rotation. Additionally, the plugin was not…

  • CVE-2026-20495HigAug 3, 2026
    risk 0.51cvss 7.8epss 0.00

    In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.

  • CVE-2026-28615HigJun 17, 2026
    risk 0.51cvss 7.8epss 0.00

    In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0081HigJun 17, 2026
    risk 0.51cvss 7.8epss 0.00

    In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0071HigJun 17, 2026
    risk 0.51cvss 7.8epss 0.00

    In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48617HigJun 17, 2026
    risk 0.51cvss 7.8epss 0.00

    In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0133HigJun 16, 2026
    risk 0.51cvss 7.8epss 0.00

    In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2025-26418HigJun 1, 2026
    risk 0.51cvss 7.8epss 0.00

    In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution…