A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local esc
In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private director
In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missin
In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due
In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission
In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission che
In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission c
In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission
In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing per
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to l
In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground
In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This
In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could le
In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input valida
In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This co
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass int
In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permis
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app t
In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug r
In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalatio
In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This coul
In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass du
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction byp
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escal
In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of scr
In Core, there is a possible way to start an activity from the background due to a missing permission check. This could
In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This c
In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead t
In network service, there is a missing permission check. This could lead to local escalation of privilege with no additi
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
There is an missing authorization issue in the system service. Since the component does not have permission check , resu
There is an missing authorization issue in the system service. Since the component does not have permission check , resu
There is an missing authorization issue in the system service. Since the component does not have permission check and pe
There is an missing authorization issue in the system service. Since the component does not have permission check , resu
There is an missing authorization issue in the system service. Since the component does not have permission check , resu
In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service wit
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts ser
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts ser
In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service
In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service
In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorde
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with n
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with n
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with n
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with n
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a
In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission ch
In power management service, there is a missing permission check. This could lead to set up power management service wit
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started