CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,000)
A local privilege escalation vulnerability allows low-privileged users to interact with a service that should be restricted. This affects systems runn...
Aug 5, 2025A Missing Authorization vulnerability in Juniper Networks Junos OS Evolved allows local low-privileged users to gain root privileges by sending packet...
Jul 11, 2025This vulnerability allows a malicious app in a non-owner profile on Android devices to activate Wi-Fi hotspot functionality without proper permissions...
Jan 17, 2025CVE-2017-13316 is a local privilege escalation vulnerability in Android's RecognitionService that allows attackers to bypass permission checks. This c...
Nov 27, 2024This vulnerability allows unauthorized clients to connect to the com.uaudio.bsd.helper service and execute privileged operations without proper valida...
Nov 25, 2024This vulnerability allows local attackers to bypass VPN network restrictions on Android devices. A missing permission check in the NetworkManagementSe...
Nov 15, 2024This vulnerability in Android's AccessibilitySettings allows an attacker to hide an enabled accessibility service from the settings menu through a log...
Nov 13, 2024This vulnerability in Android's MediaProvider allows one app to access files belonging to other apps without proper permission checks. It enables loca...
Nov 13, 2024This vulnerability allows local attackers to access the microphone without proper permission checks, enabling potential audio surveillance. It affects...
Nov 13, 2024This vulnerability allows local attackers to bypass Factory Reset Protection (FRP) on Android devices without user interaction. It enables local privi...
Sep 11, 2024This CVE describes a missing authorization vulnerability in QNAP operating systems that allows local authenticated users to access data or perform act...
Sep 6, 2024This vulnerability allows local attackers to bypass the DISALLOW_ADD_WIFI_CONFIG restriction in Android's Settings app, enabling them to add unauthori...
May 7, 2024This CVE describes a local privilege escalation vulnerability in Ant Media Server versions 2.6.0 through 2.8.2. Any unprivileged operating system user...
Apr 22, 2024This vulnerability allows authenticated attackers with low privileges to escalate to SYSTEM-level access and execute arbitrary code on affected Rapid7...
Apr 3, 2024This vulnerability allows local attackers to inject arbitrary input events without proper permission checks in Android's AccessibilityManagerService. ...
Feb 16, 2024This vulnerability allows local privilege escalation on affected Android devices without requiring user interaction. Attackers can exploit a missing p...
Dec 8, 2023This vulnerability allows an attacker to bypass the lock screen on Android devices without needing any special permissions or user interaction. It aff...
Dec 4, 2023This vulnerability in telecom services allows local attackers to escalate privileges without needing additional execution permissions, due to a missin...
Dec 4, 2023CVE-2023-42738 is a missing permission check vulnerability in the telocom service that allows local attackers to escalate privileges without requiring...
Dec 4, 2023This vulnerability in telecom services allows local attackers to write permission usage records of applications without proper authorization checks. I...
Dec 4, 2023This CVE describes a missing permission check vulnerability in telecom services that allows local attackers to escalate privileges without requiring a...
Dec 4, 2023This CVE describes a missing permission check vulnerability in telecom services that could allow local attackers to escalate privileges without needin...
Dec 4, 2023This CVE describes a missing permission check vulnerability in camera service that allows local privilege escalation. Attackers can exploit this to ga...
Dec 4, 2023This CVE describes a missing permission check in the WiFi service that allows local privilege escalation without requiring additional execution privil...
Dec 4, 2023CVE-2023-42694 is a missing permission check vulnerability in the WiFi service that allows local attackers to escalate privileges without requiring ad...
Dec 4, 2023This vulnerability in telecom services allows local attackers to escalate privileges without needing additional execution permissions. It affects syst...
Dec 4, 2023This vulnerability in Android's Telecomm component allows secondary users to silence incoming calls without proper permission checks, enabling local p...
Oct 30, 2023This vulnerability allows local attackers to bypass permission checks in Android Settings, potentially gaining elevated privileges without user intera...
Oct 30, 2023This vulnerability in Android's Package Installer allows attackers to detect whether specific apps are installed without requiring query permissions, ...
Oct 30, 2023This vulnerability in Android's Permission Manager allows attackers to bypass required permissions without user interaction, potentially gaining eleva...
Oct 30, 2023CVE-2023-21313 is a local privilege escalation vulnerability in Android Core that allows malicious apps to forward calls without user knowledge due to...
Oct 30, 2023This vulnerability in IXP Data Easy Install v6.6.14884.0 allows attackers to escalate privileges due to insufficient directory permissions. Attackers ...
Oct 19, 2023CVE-2023-40634 is a missing permission check vulnerability in phasechecksercer that allows local privilege escalation without requiring additional exe...
Oct 8, 2023This vulnerability allows unauthorized import of contacts from other users on Android devices due to a missing permission check in Telephony services....
Sep 11, 2023CVE-2023-38449 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...
Sep 4, 2023CVE-2023-38451 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...
Sep 4, 2023CVE-2023-38453 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...
Sep 4, 2023CVE-2023-38455 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...
Sep 4, 2023CVE-2023-38458 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...
Sep 4, 2023CVE-2023-38460 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...
Sep 4, 2023CVE-2023-38464 is a missing permission check vulnerability in vowifiservice that allows local attackers to escalate privileges without requiring addit...
Sep 4, 2023CVE-2023-38443 is a missing permission check vulnerability in vowifiservice that allows local privilege escalation. Attackers can exploit this to gain...
Sep 4, 2023CVE-2023-24674 is a privilege escalation vulnerability in Bludit CMS v4.0.0 that allows local attackers to gain administrative privileges by manipulat...
Sep 1, 2023This vulnerability allows local attackers to bypass device policy restrictions for Bluetooth scanning without proper permission checks. It enables loc...
Jul 13, 2023This vulnerability in telephony services allows local attackers to escalate privileges without requiring additional execution permissions. It affects ...
Jul 12, 2023CVE-2023-30916 is a missing permission check vulnerability in DMService that allows local attackers to escalate privileges without requiring additiona...
Jul 12, 2023CVE-2023-20773 is a privilege escalation vulnerability in MediaTek's vow component where a missing permission check allows local attackers to gain ele...
Jul 4, 2023This vulnerability allows a guest user on Android devices to escalate privileges without requiring any permissions or user interaction. It affects And...
Jun 28, 2023This vulnerability allows local attackers to activate or deactivate RCS (Rich Communication Services) on Android devices without proper permissions. I...
Jun 28, 2023This vulnerability allows local attackers to bypass Android's DISALLOW_DEBUGGING_FEATURES restriction, enabling unauthorized debugging and tracing cap...
Jun 15, 2023About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,000 CVEs classified as CWE-862, with 215 rated critical and 819 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free