CWE-862— Missing Authorization
7,602 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 7 of 153
- CVE-2019-2137MEDIUMCVSS 5.5EG 5.52019-08-20
In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check. This could lead to local denial of access to Emergency Services with User execution privileges needed. User interact…
- CVE-2019-2218HIGHCVSS 7.8EG 7.82019-12-06
In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could lead to local escalation of privilege by installing malicious packages with User executio…
- CVE-2019-2229MEDIUMCVSS 5.5EG 5.52019-12-06
In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne…
- CVE-2019-25139MEDIUMCVSS 6.5EG 6.52023-06-07
The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions up to, and including 1.8.1 due to missing capability checks in the ~/functions/data-reset-post.php file which makes it…
- CVE-2019-25141CRITICALCVSS 9.8EG 9.82023-06-07
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This …
- CVE-2019-25142HIGHCVSS 8.8EG 8.82023-06-07
The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and including,1.6.89 (Mesmerize) and 1.0.172 (Materialis). This is due to 'companion_disable_popup' function only checking th…
- CVE-2019-25143MEDIUMCVSS 5.4EG 5.42023-06-07
The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possibl…
- CVE-2019-25214HIGHCVSS 7.2EG 7.22024-10-16
The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to call the en…
- CVE-2019-25215HIGHCVSS 7.3EG 7.32024-10-16
The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin in versions up to, and including, 1.1.14. This makes it possible for unauthenticated attack…
- CVE-2019-25217CRITICALCVSS 9.8EG 9.82024-10-16
The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect use of an access control attribute on t…
- CVE-2019-3399HIGHCVSS 7.5EG 7.52019-04-30
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.
- CVE-2019-3835MEDIUMCVSS 5.5EG 5.52019-03-25
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the c…
- CVE-2019-3879HIGHCVSS 8.1EG 8.12019-03-25
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low p…
- CVE-2019-3886MEDIUMCVSS 5.4EG 5.42019-04-04
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of servi…
- CVE-2019-4158MEDIUMCVSS 5.4EG 5.42019-06-25
IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. IBM X-Force ID: 158574.
- CVE-2019-4446MEDIUMCVSS 5.4EG 5.42020-04-17
IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
- CVE-2019-5095MEDIUMCVSS 4.3EG 4.32019-10-31
An issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin, version 4.10.0. Authenticated users can obtain the summary for issues they do not have permission to view via the Tempo plugin.
- CVE-2019-5449MEDIUMCVSS 4.3EG 4.32019-07-30
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
- CVE-2019-5463MEDIUMCVSS 5.3EG 5.32019-09-09
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.
- CVE-2019-5470HIGHCVSS 7.5EG 7.52020-01-28
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.
- CVE-2019-5774HIGHCVSS 8.8EG 8.82019-02-19
Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloa…
- CVE-2019-5779MEDIUMCVSS 4.3EG 4.32019-02-19
Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2019-5865MEDIUMCVSS 6.5EG 6.52019-11-25
Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
- CVE-2019-5886CRITICALCVSS 9.8EG 9.82019-01-10
An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. The attacker can write arbitrary code to…
- CVE-2019-5995MEDIUMCVSS 6.5EG 6.52019-08-06
Missing authorization vulnerability exists in EOS series digital cameras (EOS-1D X firmware version 2.1.0 and earlier, EOS-1D X MKII firmware version 1.1.6 and earlier, EOS-1D C firmware version 1.4.1 and earlier, EOS 5D MARK III firmware …
- CVE-2019-6121LOWCVSS 3.7EG 3.72019-11-06
An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments, unclaimed Balance, Old Balance (at the time of December 2017…
- CVE-2019-6538CRITICALCVSS 9.3EG 6.52019-03-25
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Co…
- CVE-2019-6580CRITICALCVSS 9.8EG 9.82019-06-12
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Sive…
- CVE-2019-6790MEDIUMCVSS 4.3EG 4.32019-05-17
An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group'…
- CVE-2019-6961MEDIUMCVSS 6.5EG 6.52019-06-20
Incorrect access control in actionHandlerUtility.php in the RDK RDKB-20181217-1 WebUI module allows a logged in user to control DDNS, QoS, RIP, and other privileged configurations (intended only for the network operator) by sending an HTTP…
- CVE-2019-7272MEDIUMCVSS 5.3EG 5.32019-07-01
Optergy Proton/Enterprise devices allow Username Disclosure.
- CVE-2019-8445MEDIUMCVSS 5.3EG 5.32019-08-23
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
- CVE-2019-8855MEDIUMCVSS 6.3EG 6.32020-10-27
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to access restricted files.
- CVE-2019-8856LOWCVSS 3.3EG 3.32020-10-27
An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was addressed with improved state handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Updat…
- CVE-2019-8857LOWCVSS 3.3EG 3.32020-10-27
The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if Live Photo is disabled in the Share Sh…
- CVE-2019-9002CRITICALCVSS 9.8EG 9.82019-02-22
An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original d…
- CVE-2019-9171LOWCVSS 3.7EG 3.72019-04-17
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).
- CVE-2019-9224MEDIUMCVSS 5.3EG 5.32019-04-17
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 4 of 5).
- CVE-2019-9263HIGHCVSS 7.8EG 7.82019-09-27
In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- CVE-2019-9295HIGHCVSS 7.8EG 7.82019-09-27
In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local escalation of privilege with User execution privileges needed. User interaction is needed…
- CVE-2019-9323MEDIUMCVSS 5.3EG 5.32019-09-27
In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper image with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2019-9351LOWCVSS 3.3EG 3.32019-09-27
In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to local limited information disclosure with no additional exe…
- CVE-2019-9377LOWCVSS 3.3EG 3.32019-09-27
In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to a local information disclosure of metadata about the biomet…
- CVE-2019-9380MEDIUMCVSS 6.5EG 6.52019-09-27
In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. This could lead to a user mistakenly changing permission settings with no additional execution privileges needed. User interaction is needed …
- CVE-2019-9482MEDIUMCVSS 5.3EG 5.32019-03-01
In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (ev…
- CVE-2019-9574HIGHCVSS 7.5EG 7.52019-03-05
The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role.
- CVE-2019-9713HIGHCVSS 7.5EG 7.52019-03-12
An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
- CVE-2019-9742HIGHCVSS 7.5EG 7.52019-03-13
gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\gdwfpcd device are not p…
- CVE-2019-9924HIGHCVSS 7.8EG 7.82019-03-22
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
- CVE-2019-9974CRITICALCVSS 9.1EG 9.12019-04-11
diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack.
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →