In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could l
In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permissi
In DomainVerificationService, there is a possible way to access app domain verification information due to a missing per
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to mi
In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information wit
In getNodeValue of USCCDMPlugin.java, there is a possible disclosure of ICCID due to a missing permission check. This co
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf
Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect
In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This
In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. Thi
In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc
In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a m
In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request lo
In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced i
In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local info
In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could l
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf
In Content, there is a possible way to learn about an account present on the device due to a missing permission check. T
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check
In ContentService, there is a possible way to check if the given account exists on the device due to a missing permissio
In Content, there is a possible way to check if the given account exists on the device due to a missing permission check
In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This
In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission d
In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission chec
In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead t
In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lea
In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to lo
In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could
In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no
In music service, there is a missing permission check. This could lead to local denial of service in music service with
In messaging service, there is a missing permission check. This could lead to local denial of service in messaging servi
In telephony service, there is a missing permission check. This could lead to local information disclosure with no addit
In telephony service, there is a missing permission check. This could lead to local information disclosure with no addit
In messaging service, there is a missing permission check. This could lead to access unexpected provider in contacts ser
In Gallery service, there is a missing permission check. This could lead to local denial of service in Gallery service w
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with
In messaging service, there is a missing permission check. This could lead to local information disclosure with no addit
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService.java, there is a possible way to learn about the n
In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission check. This could lead
snipe-it is vulnerable to Missing Authorization
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started