In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for
In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction f
In registerGsmaServiceIntentReceiver of ShannonRcsService.java, there is a possible way to activate/deactivate RCS servi
In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalati
In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalati
Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via th
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no add
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no add
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit
In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a de
In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device
In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile
Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin p
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no
In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This
In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with
In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no add
An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions
In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactl
In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could l
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due t
In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This co
In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. Th
In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check.
In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalati
In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead
In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to lo
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no a
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started