CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,000
Total CVEs
215
Critical
819
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 107
2 Sap 31
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,000)

CVE-2025-41698
7.8

A local privilege escalation vulnerability allows low-privileged users to interact with a service that should be restricted. This affects systems runn...

Aug 5, 2025
CVE-2025-52954
7.8

A Missing Authorization vulnerability in Juniper Networks Junos OS Evolved allows local low-privileged users to gain root privileges by sending packet...

Jul 11, 2025
CVE-2018-9382
7.8

This vulnerability allows a malicious app in a non-owner profile on Android devices to activate Wi-Fi hotspot functionality without proper permissions...

Jan 17, 2025
CVE-2017-13316
7.8

CVE-2017-13316 is a local privilege escalation vulnerability in Android's RecognitionService that allows attackers to bypass permission checks. This c...

Nov 27, 2024
CVE-2024-8272
7.8

This vulnerability allows unauthorized clients to connect to the com.uaudio.bsd.helper service and execute privileged operations without proper valida...

Nov 25, 2024
CVE-2017-13314
7.8

This vulnerability allows local attackers to bypass VPN network restrictions on Android devices. A missing permission check in the NetworkManagementSe...

Nov 15, 2024
CVE-2024-43087
7.8

This vulnerability in Android's AccessibilitySettings allows an attacker to hide an enabled accessibility service from the settings menu through a log...

Nov 13, 2024
CVE-2024-43089
7.8

This vulnerability in Android's MediaProvider allows one app to access files belonging to other apps without proper permission checks. It enables loca...

Nov 13, 2024
CVE-2024-40661
7.8

This vulnerability allows local attackers to access the microphone without proper permission checks, enabling potential audio surveillance. It affects...

Nov 13, 2024
CVE-2024-40650
7.8

This vulnerability allows local attackers to bypass Factory Reset Protection (FRP) on Android devices without user interaction. It enables local privi...

Sep 11, 2024
CVE-2023-39298
7.8

This CVE describes a missing authorization vulnerability in QNAP operating systems that allows local authenticated users to access data or perform act...

Sep 6, 2024
CVE-2024-23704
7.8

This vulnerability allows local attackers to bypass the DISALLOW_ADD_WIFI_CONFIG restriction in Android's Settings app, enabling them to add unauthori...

May 7, 2024
CVE-2024-32656
7.8

This CVE describes a local privilege escalation vulnerability in Ant Media Server versions 2.6.0 through 2.8.2. Any unprivileged operating system user...

Apr 22, 2024
CVE-2024-0394
7.8

This vulnerability allows authenticated attackers with low privileges to escalate to SYSTEM-level access and execute arbitrary code on affected Rapid7...

Apr 3, 2024
CVE-2024-0038
7.8

This vulnerability allows local attackers to inject arbitrary input events without proper permission checks in Android's AccessibilityManagerService. ...

Feb 16, 2024
CVE-2023-48402
7.8

This vulnerability allows local privilege escalation on affected Android devices without requiring user interaction. Attackers can exploit a missing p...

Dec 8, 2023
CVE-2023-40094
7.8

This vulnerability allows an attacker to bypass the lock screen on Android devices without needing any special permissions or user interaction. It aff...

Dec 4, 2023
CVE-2023-42736
7.8

This vulnerability in telecom services allows local attackers to escalate privileges without needing additional execution permissions, due to a missin...

Dec 4, 2023
CVE-2023-42738
7.8

CVE-2023-42738 is a missing permission check vulnerability in the telocom service that allows local attackers to escalate privileges without requiring...

Dec 4, 2023
CVE-2023-42740
7.8

This vulnerability in telecom services allows local attackers to write permission usage records of applications without proper authorization checks. I...

Dec 4, 2023
CVE-2023-42743
7.8

This CVE describes a missing permission check vulnerability in telecom services that allows local attackers to escalate privileges without requiring a...

Dec 4, 2023
CVE-2023-42745
7.8

This CVE describes a missing permission check vulnerability in telecom services that could allow local attackers to escalate privileges without needin...

Dec 4, 2023
CVE-2023-42747
7.8

This CVE describes a missing permission check vulnerability in camera service that allows local privilege escalation. Attackers can exploit this to ga...

Dec 4, 2023
CVE-2023-42692
7.8

This CVE describes a missing permission check in the WiFi service that allows local privilege escalation without requiring additional execution privil...

Dec 4, 2023
CVE-2023-42694
7.8

CVE-2023-42694 is a missing permission check vulnerability in the WiFi service that allows local attackers to escalate privileges without requiring ad...

Dec 4, 2023
CVE-2023-42696
7.8

This vulnerability in telecom services allows local attackers to escalate privileges without needing additional execution permissions. It affects syst...

Dec 4, 2023
CVE-2023-21378
7.8

This vulnerability in Android's Telecomm component allows secondary users to silence incoming calls without proper permission checks, enabling local p...

Oct 30, 2023
CVE-2023-21388
7.8

This vulnerability allows local attackers to bypass permission checks in Android Settings, potentially gaining elevated privileges without user intera...

Oct 30, 2023
CVE-2023-21328
7.8

This vulnerability in Android's Package Installer allows attackers to detect whether specific apps are installed without requiring query permissions, ...

Oct 30, 2023
CVE-2023-21341
7.8

This vulnerability in Android's Permission Manager allows attackers to bypass required permissions without user interaction, potentially gaining eleva...

Oct 30, 2023
CVE-2023-21313
7.8

CVE-2023-21313 is a local privilege escalation vulnerability in Android Core that allows malicious apps to forward calls without user knowledge due to...

Oct 30, 2023
CVE-2023-27792
7.8

This vulnerability in IXP Data Easy Install v6.6.14884.0 allows attackers to escalate privileges due to insufficient directory permissions. Attackers ...

Oct 19, 2023
CVE-2023-40634
7.8

CVE-2023-40634 is a missing permission check vulnerability in phasechecksercer that allows local privilege escalation without requiring additional exe...

Oct 8, 2023
CVE-2023-35665
7.8

This vulnerability allows unauthorized import of contacts from other users on Android devices due to a missing permission check in Telephony services....

Sep 11, 2023
CVE-2023-38449
7.8

CVE-2023-38449 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...

Sep 4, 2023
CVE-2023-38451
7.8

CVE-2023-38451 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...

Sep 4, 2023
CVE-2023-38453
7.8

CVE-2023-38453 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...

Sep 4, 2023
CVE-2023-38455
7.8

CVE-2023-38455 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...

Sep 4, 2023
CVE-2023-38458
7.8

CVE-2023-38458 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...

Sep 4, 2023
CVE-2023-38460
7.8

CVE-2023-38460 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...

Sep 4, 2023
CVE-2023-38464
7.8

CVE-2023-38464 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...

Sep 4, 2023
CVE-2023-38443
7.8

CVE-2023-38443 is a missing permission check vulnerability in vowifiservice that allows local privilege escalation. Attackers can exploit this to gain...

Sep 4, 2023
CVE-2023-24674
7.8

CVE-2023-24674 is a privilege escalation vulnerability in Bludit CMS v4.0.0 that allows local attackers to gain administrative privileges by manipulat...

Sep 1, 2023
CVE-2023-21247
7.8

This vulnerability allows local attackers to bypass device policy restrictions for Bluetooth scanning without proper permission checks. It enables loc...

Jul 13, 2023
CVE-2023-30928
7.8

This vulnerability in telephony services allows local attackers to escalate privileges without requiring additional execution permissions. It affects ...

Jul 12, 2023
CVE-2023-30916
7.8

CVE-2023-30916 is a missing permission check vulnerability in DMService that allows local attackers to escalate privileges without requiring additiona...

Jul 12, 2023
CVE-2023-20773
7.8

CVE-2023-20773 is a privilege escalation vulnerability in MediaTek's vow component where a missing permission check allows local attackers to gain ele...

Jul 4, 2023
CVE-2023-21185
7.8

This vulnerability allows a guest user on Android devices to escalate privileges without requiring any permissions or user interaction. It affects And...

Jun 28, 2023
CVE-2023-21149
7.8

This vulnerability allows local attackers to activate or deactivate RCS (Rich Communication Services) on Android devices without proper permissions. I...

Jun 28, 2023
CVE-2023-21122
7.8

This vulnerability allows local attackers to bypass Android's DISALLOW_DEBUGGING_FEATURES restriction, enabling unauthorized debugging and tracing cap...

Jun 15, 2023

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,000 CVEs classified as CWE-862, with 215 rated critical and 819 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free