Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 163/188
7.8
CVE-2022-0492 KEV

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th

7.8
CVE-2022-20053

In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local

7.8
CVE-2022-20054

In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local esc

7.8
CVE-2021-39697

In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private director

7.8
CVE-2021-39706

In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missin

7.8
CVE-2021-39734

In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due

7.8
CVE-2021-39743

In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission

7.8
CVE-2021-39749

In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission che

7.8
CVE-2021-39750

In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission c

7.8
CVE-2021-39758

In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission

7.8
CVE-2021-39768

In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing per

7.8
CVE-2022-20002

In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to l

7.8
CVE-2021-39808

In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground

7.8
CVE-2022-20084

In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This

7.8
CVE-2022-20093

In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could le

7.8
CVE-2022-20004

In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input valida

7.8
CVE-2021-39738

In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This co

7.8
CVE-2022-30594

The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass int

7.8
CVE-2022-20133

In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permis

7.8
CVE-2022-20138

In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app t

7.8
CVE-2022-20204

In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug r

7.8
CVE-2022-21777

In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalatio

7.8
CVE-2022-26429

In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This coul

7.8
CVE-2022-20348

In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass du

7.8
CVE-2022-20349

In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction byp

7.8
CVE-2022-20360

In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escal

7.8
CVE-2022-20274

In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of scr

7.8
CVE-2022-20281

In Core, there is a possible way to start an activity from the background due to a missing permission check. This could

7.8
CVE-2022-20282

In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This c

7.8
CVE-2022-20329

In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead t

7.8
CVE-2022-39119

In network service, there is a missing permission check. This could lead to local escalation of privilege with no additi

7.8
CVE-2022-40673

KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.

7.8
CVE-2022-20430

There is an missing authorization issue in the system service. Since the component does not have permission check , resu

7.8
CVE-2022-20431

There is an missing authorization issue in the system service. Since the component does not have permission check , resu

7.8
CVE-2022-20432

There is an missing authorization issue in the system service. Since the component does not have permission check and pe

7.8
CVE-2022-20433

There is an missing authorization issue in the system service. Since the component does not have permission check , resu

7.8
CVE-2022-20434

There is an missing authorization issue in the system service. Since the component does not have permission check , resu

7.8
CVE-2022-2985

In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service wit

7.8
CVE-2022-38669

In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts ser

7.8
CVE-2022-38670

In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts ser

7.8
CVE-2022-38698

In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service

7.8
CVE-2022-39080

In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service

7.8
CVE-2022-39107

In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorde

7.8
CVE-2022-39108

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with n

7.8
CVE-2022-39109

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with n

7.8
CVE-2022-39110

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with n

7.8
CVE-2022-39111

In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with n

7.8
CVE-2022-20450

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a

7.8
CVE-2022-20451

In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission ch

7.8
CVE-2022-39090

In power management service, there is a missing permission check. This could lead to set up power management service wit

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started