Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 147/188
7.8
CVE-2023-21122

In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for

7.8
CVE-2023-21123

In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction f

7.8
CVE-2023-21149

In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS servi

7.8
CVE-2023-21185

In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalati

7.8
CVE-2023-20773

In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalati

7.8
CVE-2023-36624

Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via th

7.8
CVE-2023-30916

In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no add

7.8
CVE-2023-30917

In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no add

7.8
CVE-2023-30928

In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit

7.8
CVE-2023-30929

In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit

7.8
CVE-2023-21247

In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a de

7.8
CVE-2023-21248

In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device

7.8
CVE-2023-21257

In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile

7.8
CVE-2023-24674

Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin p

7.8
CVE-2023-38443

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38444

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38449

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38450

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38451

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38452

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38453

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38455

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38456

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38458

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38459

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38460

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-38464

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no

7.8
CVE-2023-35665

In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This

7.8
CVE-2023-40634

In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with

7.8
CVE-2023-40635

In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no add

7.8
CVE-2023-27792

An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions

7.8
CVE-2021-39810

In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactl

7.8
CVE-2023-21313

In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could l

7.8
CVE-2023-21328

In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due t

7.8
CVE-2023-21341

In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This co

7.8
CVE-2023-21373

In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. Th

7.8
CVE-2023-21378

In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check.

7.8
CVE-2023-21388

In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalati

7.8
CVE-2023-21389

In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead

7.8
CVE-2023-21393

In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to lo

7.8
CVE-2023-42681

In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no a

7.8
CVE-2023-42685

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42686

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42687

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42688

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42689

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42690

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42691

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42692

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

7.8
CVE-2023-42693

In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started