CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
8,934 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 27 of 179
- CVE-2022-23617MEDIUMCVSS 6.5EG 6.52022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit right can copy the content of a page it does not have access to by using it as template of a n…
- CVE-2022-23621MEDIUMCVSS 5.5EG 5.52022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties…
- CVE-2022-23642CRITICALCVSS 8.8EG 9.02022-02-18
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git conf…
- CVE-2022-2369MEDIUMCVSS 4.3EG 4.32022-08-01
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
- CVE-2022-2370MEDIUMCVSS 6.5EG 6.52022-08-01
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
- CVE-2022-23709MEDIUMCVSS 4.3EG 4.32022-03-03
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modifi…
- CVE-2022-2373MEDIUMCVSS 5.3EG 5.32022-08-29
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
- CVE-2022-2376MEDIUMCVSS 5.3EG 5.32022-09-05
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users
- CVE-2022-2377MEDIUMCVSS 4.3EG 4.32022-08-22
The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog
- CVE-2022-2379HIGHCVSS 7.5EG 7.52022-08-15
The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as emai…
- CVE-2022-2382MEDIUMCVSS 4.3EG 4.32022-08-22
The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow th…
- CVE-2022-2389MEDIUMCVSS 4.3EG 4.32022-08-22
The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenti…
- CVE-2022-23944CRITICALCVSS 9.1EG 9.12022-01-25
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
- CVE-2022-23945HIGHCVSS 7.5EG 7.52022-01-25
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
- CVE-2022-2405MEDIUMCVSS 4.3EG 4.32022-09-26
The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup
- CVE-2022-24190HIGHCVSS 7.5EG 7.52022-11-28
The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account t…
- CVE-2022-24317HIGHCVSS 7.5EG 7.52022-02-09
A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
- CVE-2022-24450HIGHCVSS 8.8EG 8.82022-02-08
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.
- CVE-2022-2450MEDIUMCVSS 4.3EG 4.32022-11-14
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.
- CVE-2022-2459LOWCVSS 2.7EG 2.72022-08-05
An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project ev…
- CVE-2022-24594MEDIUMCVSS 5.3EG 5.32022-02-25
In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
- CVE-2022-24595CRITICALCVSS 9.8EG 9.82022-03-18
Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Control in usr/bin/afb-daemon. To exploit the vulnerability, an attacker should send a well-crafted HTTP (or WebSocket) req…
- CVE-2022-2461MEDIUMCVSS 5.3EG 5.32022-09-06
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translat…
- CVE-2022-24669MEDIUMCVSS 6.5EG 6.52022-10-27
It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.
- CVE-2022-24768CRITICALCVSS 9.9EG 9.92022-03-23
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privi…
- CVE-2022-24896MEDIUMCVSS 4.3EG 4.32022-06-09
Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widget…
- CVE-2022-24986HIGHCVSS 7.8EG 7.82022-02-26
KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling t…
- CVE-2022-25190MEDIUMCVSS 4.3EG 4.32022-02-15
A missing permission check in Jenkins Conjur Secrets Plugin 1.0.11 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
- CVE-2022-25193MEDIUMCVSS 6.5EG 6.52022-02-15
Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method…
- CVE-2022-25195MEDIUMCVSS 4.3EG 4.32022-02-15
A missing permission check in Jenkins autonomiq Plugin 1.15 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
- CVE-2022-25199HIGHCVSS 8.8EG 8.82022-02-15
A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.
- CVE-2022-25201MEDIUMCVSS 6.5EG 6.52022-02-15
Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method,…
- CVE-2022-25206HIGHCVSS 8.8EG 8.82022-02-15
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials.
- CVE-2022-25208HIGHCVSS 8.8EG 8.82022-02-15
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
- CVE-2022-25211HIGHCVSS 8.8EG 8.82022-02-15
A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials.
- CVE-2022-25342HIGHCVSS 8.1EG 8.12022-04-20
An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not properly validate requests for access to data and functionality under the /mngset/authset pa…
- CVE-2022-2543MEDIUMCVSS 6.1EG 6.12022-09-05
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved…
- CVE-2022-2552MEDIUMCVSS 5.3EG 5.32022-08-22
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
- CVE-2022-25768HIGHCVSS 7.0EG 7.02024-09-18
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mauti…
- CVE-2022-25810MEDIUMCVSS 6.5EG 6.52022-08-22
The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab (/wp-admin/admin.php?page=tp_utils), which can be used/executed as the lowest-privileg…
- CVE-2022-26102MEDIUMCVSS 5.4EG 5.42022-03-10
Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP …
- CVE-2022-26103MEDIUMCVSS 5.3EG 5.32022-03-10
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
- CVE-2022-26104MEDIUMCVSS 5.3EG 5.32022-03-10
SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message.
- CVE-2022-26423HIGHCVSS 8.2EG 8.22022-10-21
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
- CVE-2022-26429HIGHCVSS 7.8EG 7.82022-08-01
In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2022-26546CRITICALCVSS 9.1EG 9.12022-03-31
Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.
- CVE-2022-2657MEDIUMCVSS 4.3EG 4.32022-09-05
The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors …
- CVE-2022-26581MEDIUMCVSS 6.8EG 6.82022-12-16
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in ADB daemon. The attacker must have physical USB access to t…
- CVE-2022-26703LOWCVSS 2.4EG 2.42022-05-26
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A person with physical access to an iOS device may be able to access photos from the lock screen.
- CVE-2022-2696MEDIUMCVSS 6.3EG 6.52022-11-03
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonc…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →