CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Yearly Trend
Top Affected Vendors
All Missing Authorization CVEs (3,003)
This vulnerability allows local attackers to activate or deactivate RCS (Rich Communication Services) on Android devices without proper permissions. I...
Jun 28, 2023This vulnerability allows local attackers to bypass Android's DISALLOW_DEBUGGING_FEATURES restriction, enabling unauthorized debugging and tracing cap...
Jun 15, 2023CVE-2022-48392 is a missing permission check vulnerability in the dialer service on Unisoc chipsets, allowing local attackers to escalate privileges w...
Jun 6, 2023CVE-2022-48390 is a missing permission check vulnerability in telephony services that allows local attackers to escalate privileges without requiring ...
Jun 6, 2023CVE-2022-48368 is a missing permission check vulnerability in the audio service that allows local attackers to escalate privileges without requiring a...
May 9, 2023CVE-2022-48383 is a missing permission check vulnerability in the srtd service that allows local attackers to escalate privileges without requiring ad...
May 9, 2023CVE-2022-48388 is a missing permission check vulnerability in the powerEx service that allows local attackers to escalate privileges without requiring...
May 9, 2023This CVE describes a missing permission check vulnerability in the audio service of certain systems, allowing local attackers to escalate privileges w...
May 9, 2023CVE-2022-48245 is a missing permission check vulnerability in the audio service that allows local attackers to escalate privileges without requiring a...
May 9, 2023This CVE describes a missing permission check vulnerability in the audio service that could allow local attackers to escalate privileges without requi...
May 9, 2023CVE-2022-48249 is a missing permission check vulnerability in the audio service that allows local attackers to escalate privileges without requiring a...
May 9, 2023CVE-2022-44433 is a missing permission check vulnerability in the phoneEx service on Unisoc chipsets. This allows local attackers to escalate privileg...
May 9, 2023This vulnerability allows a local attacker to take over the screen display and swap display content without user interaction due to a missing permissi...
Apr 19, 2023This vulnerability allows local attackers to bypass permission checks in Android's Transcode Permission Controllers, enabling privilege escalation wit...
Mar 24, 2023This Android vulnerability allows a guest user account to change network settings of an admin user due to a missing permission check in the WiFi servi...
Mar 24, 2023This vulnerability allows local attackers to bypass permission checks in Android's Transcode Permission Controllers, potentially gaining elevated priv...
Mar 24, 2023This vulnerability allows local attackers to bypass permission checks in Android's Transcode Permission Controllers, potentially gaining elevated priv...
Mar 24, 2023This vulnerability allows guest users on Android 13 devices to escalate privileges locally by accessing the AddSupervisedUserActivity without proper p...
Mar 24, 2023CVE-2022-47361 is a missing permission check vulnerability in firewall services that allows local attackers to escalate privileges. Attackers need sys...
Feb 12, 2023CVE-2022-21777 is a permission bypass vulnerability in Autoboot that allows local attackers to escalate privileges without user interaction. This affe...
Jul 6, 2022This vulnerability allows local attackers to submit falsified bug reports without proper permission checks, potentially leading to privilege escalatio...
Jun 15, 2022This vulnerability allows local attackers to bypass user interaction requirements for Bluetooth discoverable timeout settings due to a missing permiss...
Jun 15, 2022This vulnerability in Android's CarSettings allows Bluetooth device pairing without user consent due to a missing permission check. It enables local p...
May 10, 2022This vulnerability allows local attackers to access any slice URI on Android devices due to improper input validation in the SliceManagerService. It e...
May 10, 2022This vulnerability in MediaTek telephony components allows local attackers to disable SMS message reception without proper permission checks. It enabl...
May 3, 2022This vulnerability in Android's incfs (incremental filesystem) allows attackers with system execution privileges to mount filesystems on arbitrary pat...
Mar 30, 2022This vulnerability in Android's PackageManager allows malicious apps to update the last usage time of other packages without proper permission checks....
Mar 30, 2022This vulnerability allows local attackers to bypass Android's activity protection mechanisms and launch non-exported activities without proper permiss...
Mar 30, 2022This vulnerability allows malicious apps to launch foreground activities from the background without proper permission checks in Android's WindowManag...
Mar 30, 2022This vulnerability in Android's RCS messaging system allows local attackers to send messages without proper permissions due to a missing permission ch...
Mar 16, 2022This vulnerability allows local privilege escalation in MediaTek's IMS service due to a missing permission check. Attackers can gain elevated privileg...
Mar 10, 2022This vulnerability in Android's MediaProvider allows local attackers to access media collections without proper permission checks. It enables local pr...
Feb 11, 2022This Bluetooth vulnerability allows local attackers to escalate privileges without user interaction by exploiting a missing permission check. It affec...
Feb 9, 2022This vulnerability allows local attackers to bypass permission checks in a MediaTek system service, potentially gaining elevated privileges without us...
Feb 9, 2022This Android kernel vulnerability allows local attackers to bypass PIN protection on device settings without requiring user interaction. It enables pr...
Dec 15, 2021CVE-2021-0999 is a local privilege escalation vulnerability in Android 12 that allows attackers to manipulate Bluetooth A2DP device connections withou...
Dec 15, 2021This vulnerability in Android 12's Wi-Fi service allows local attackers to detect whether specific apps are installed without proper permissions. It e...
Dec 15, 2021This vulnerability in Android's permission system allows local attackers to escalate privileges without user interaction. It affects Android 12 device...
Dec 15, 2021This macOS vulnerability allows malicious applications to bypass Privacy preferences, potentially accessing protected data without user consent. It af...
Sep 8, 2021This vulnerability allows unauthenticated attackers to execute arbitrary code on rConfig servers by uploading a malicious ZIP file to the insecure /up...
Aug 20, 2021This vulnerability allows local attackers to escalate privileges on Android 11 devices by supplying malicious values to the GPS HAL handler without re...
Jun 22, 2021This vulnerability in Android 11's Settings app allows attackers to disable always-on VPN connections without proper permission checks. It enables loc...
Jun 21, 2021This vulnerability allows local attackers to bypass permission checks in Android's notification system, potentially gaining elevated privileges withou...
Jun 21, 2021CVE-2021-0491 is a local privilege escalation vulnerability in Android's memory management driver where a missing permission check allows attackers to...
Jun 11, 2021This vulnerability in the Linux kernel allows user applications to send kernel RPC messages through the fastrpc driver, bypassing intended access cont...
Mar 15, 2021This Android vulnerability allows local attackers to trigger provisioning URLs and modify telephony settings without proper permission checks during d...
Mar 10, 2021This Android vulnerability allows attackers to connect devices to untrusted WiFi networks through lock screen notifications, potentially enabling loca...
Mar 10, 2021This vulnerability in Android's IMS phone call tracking system allows misattribution of video call data usage to incorrect applications. It enables lo...
Mar 10, 2021CVE-2020-23740 is a local privilege escalation vulnerability in DriverGenius driver update software. Attackers can exploit this vulnerability to eleva...
Dec 3, 2020SAP Solution Tools Plug-In (ST-PI) contains an authorization bypass vulnerability where authenticated users can access sensitive information without p...
Feb 10, 2026About Missing Authorization (CWE-862)
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Our database tracks 3,003 CVEs classified as CWE-862, with 217 rated critical and 820 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.
External reference: View CWE-862 on MITRE CWE →
Monitor Missing Authorization Vulnerabilities
Get alerted when new Missing Authorization CVEs affect your infrastructure.
Start Monitoring Free