CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,003
Total CVEs
217
Critical
820
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 107
2 Sap 31
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Wpdeveloper 11
9 Q Free 11
10 Apache 10

All Missing Authorization CVEs (3,003)

CVE-2023-21149
7.8

This vulnerability allows local attackers to activate or deactivate RCS (Rich Communication Services) on Android devices without proper permissions. I...

Jun 28, 2023
CVE-2023-21122
7.8

This vulnerability allows local attackers to bypass Android's DISALLOW_DEBUGGING_FEATURES restriction, enabling unauthorized debugging and tracing cap...

Jun 15, 2023
CVE-2022-48392
7.8

CVE-2022-48392 is a missing permission check vulnerability in the dialer service on Unisoc chipsets, allowing local attackers to escalate privileges w...

Jun 6, 2023
CVE-2022-48390
7.8

CVE-2022-48390 is a missing permission check vulnerability in telephony services that allows local attackers to escalate privileges without requiring ...

Jun 6, 2023
CVE-2022-48368
7.8

CVE-2022-48368 is a missing permission check vulnerability in the audio service that allows local attackers to escalate privileges without requiring a...

May 9, 2023
CVE-2022-48383
7.8

CVE-2022-48383 is a missing permission check vulnerability in the srtd service that allows local attackers to escalate privileges without requiring ad...

May 9, 2023
CVE-2022-48388
7.8

CVE-2022-48388 is a missing permission check vulnerability in the powerEx service that allows local attackers to escalate privileges without requiring...

May 9, 2023
CVE-2022-48243
7.8

This CVE describes a missing permission check vulnerability in the audio service of certain systems, allowing local attackers to escalate privileges w...

May 9, 2023
CVE-2022-48245
7.8

CVE-2022-48245 is a missing permission check vulnerability in the audio service that allows local attackers to escalate privileges without requiring a...

May 9, 2023
CVE-2022-48247
7.8

This CVE describes a missing permission check vulnerability in the audio service that could allow local attackers to escalate privileges without requi...

May 9, 2023
CVE-2022-48249
7.8

CVE-2022-48249 is a missing permission check vulnerability in the audio service that allows local attackers to escalate privileges without requiring a...

May 9, 2023
CVE-2022-44433
7.8

CVE-2022-44433 is a missing permission check vulnerability in the phoneEx service on Unisoc chipsets. This allows local attackers to escalate privileg...

May 9, 2023
CVE-2023-21094
7.8

This vulnerability allows a local attacker to take over the screen display and swap display content without user interaction due to a missing permissi...

Apr 19, 2023
CVE-2023-21015
7.8

This vulnerability allows local attackers to bypass permission checks in Android's Transcode Permission Controllers, enabling privilege escalation wit...

Mar 24, 2023
CVE-2023-21021
7.8

This Android vulnerability allows a guest user account to change network settings of an admin user due to a missing permission check in the WiFi servi...

Mar 24, 2023
CVE-2023-21002
7.8

This vulnerability allows local attackers to bypass permission checks in Android's Transcode Permission Controllers, potentially gaining elevated priv...

Mar 24, 2023
CVE-2023-21004
7.8

This vulnerability allows local attackers to bypass permission checks in Android's Transcode Permission Controllers, potentially gaining elevated priv...

Mar 24, 2023
CVE-2023-20959
7.8

This vulnerability allows guest users on Android 13 devices to escalate privileges locally by accessing the AddSupervisedUserActivity without proper p...

Mar 24, 2023
CVE-2022-47361
7.8

CVE-2022-47361 is a missing permission check vulnerability in firewall services that allows local attackers to escalate privileges. Attackers need sys...

Feb 12, 2023
CVE-2022-21777
7.8

CVE-2022-21777 is a permission bypass vulnerability in Autoboot that allows local attackers to escalate privileges without user interaction. This affe...

Jul 6, 2022
CVE-2022-20204
7.8

This vulnerability allows local attackers to submit falsified bug reports without proper permission checks, potentially leading to privilege escalatio...

Jun 15, 2022
CVE-2022-20133
7.8

This vulnerability allows local attackers to bypass user interaction requirements for Bluetooth discoverable timeout settings due to a missing permiss...

Jun 15, 2022
CVE-2021-39738
7.8

This vulnerability in Android's CarSettings allows Bluetooth device pairing without user consent due to a missing permission check. It enables local p...

May 10, 2022
CVE-2022-20004
7.8

This vulnerability allows local attackers to access any slice URI on Android devices due to improper input validation in the SliceManagerService. It e...

May 10, 2022
CVE-2022-20093
7.8

This vulnerability in MediaTek telephony components allows local attackers to disable SMS message reception without proper permission checks. It enabl...

May 3, 2022
CVE-2022-20002
7.8

This vulnerability in Android's incfs (incremental filesystem) allows attackers with system execution privileges to mount filesystems on arbitrary pat...

Mar 30, 2022
CVE-2021-39743
7.8

This vulnerability in Android's PackageManager allows malicious apps to update the last usage time of other packages without proper permission checks....

Mar 30, 2022
CVE-2021-39749
7.8

This vulnerability allows local attackers to bypass Android's activity protection mechanisms and launch non-exported activities without proper permiss...

Mar 30, 2022
CVE-2021-39758
7.8

This vulnerability allows malicious apps to launch foreground activities from the background without proper permission checks in Android's WindowManag...

Mar 30, 2022
CVE-2021-39734
7.8

This vulnerability in Android's RCS messaging system allows local attackers to send messages without proper permissions due to a missing permission ch...

Mar 16, 2022
CVE-2022-20053
7.8

This vulnerability allows local privilege escalation in MediaTek's IMS service due to a missing permission check. Attackers can gain elevated privileg...

Mar 10, 2022
CVE-2021-39662
7.8

This vulnerability in Android's MediaProvider allows local attackers to access media collections without proper permission checks. It enables local pr...

Feb 11, 2022
CVE-2022-20043
7.8

This Bluetooth vulnerability allows local attackers to escalate privileges without user interaction by exploiting a missing permission check. It affec...

Feb 9, 2022
CVE-2022-20024
7.8

This vulnerability allows local attackers to bypass permission checks in a MediaTek system service, potentially gaining elevated privileges without us...

Feb 9, 2022
CVE-2021-39651
7.8

This Android kernel vulnerability allows local attackers to bypass PIN protection on device settings without requiring user interaction. It enables pr...

Dec 15, 2021
CVE-2021-0999
7.8

CVE-2021-0999 is a local privilege escalation vulnerability in Android 12 that allows attackers to manipulate Bluetooth A2DP device connections withou...

Dec 15, 2021
CVE-2021-1004
7.8

This vulnerability in Android 12's Wi-Fi service allows local attackers to detect whether specific apps are installed without proper permissions. It e...

Dec 15, 2021
CVE-2021-0923
7.8

This vulnerability in Android's permission system allows local attackers to escalate privileges without user interaction. It affects Android 12 device...

Dec 15, 2021
CVE-2021-30713
7.8

This macOS vulnerability allows malicious applications to bypass Privacy preferences, potentially accessing protected data without user consent. It af...

Sep 8, 2021
CVE-2020-27464
7.8

This vulnerability allows unauthenticated attackers to execute arbitrary code on rConfig servers by uploading a malicious ZIP file to the insecure /up...

Aug 20, 2021
CVE-2021-0547
7.8

This vulnerability allows local attackers to escalate privileges on Android 11 devices by supplying malicious values to the GPS HAL handler without re...

Jun 22, 2021
CVE-2021-0505
7.8

This vulnerability in Android 11's Settings app allows attackers to disable always-on VPN connections without proper permission checks. It enables loc...

Jun 21, 2021
CVE-2021-0513
7.8

This vulnerability allows local attackers to bypass permission checks in Android's notification system, potentially gaining elevated privileges withou...

Jun 21, 2021
CVE-2021-0491
7.8

CVE-2021-0491 is a local privilege escalation vulnerability in Android's memory management driver where a missing permission check allows attackers to...

Jun 11, 2021
CVE-2021-28375
7.8

This vulnerability in the Linux kernel allows user applications to send kernel RPC messages through the fastrpc driver, bypassing intended access cont...

Mar 15, 2021
CVE-2021-0380
7.8

This Android vulnerability allows local attackers to trigger provisioning URLs and modify telephony settings without proper permission checks during d...

Mar 10, 2021
CVE-2021-0385
7.8

This Android vulnerability allows attackers to connect devices to untrusted WiFi networks through lock screen notifications, potentially enabling loca...

Mar 10, 2021
CVE-2021-0388
7.8

This vulnerability in Android's IMS phone call tracking system allows misattribution of video call data usage to incorrect applications. It enables lo...

Mar 10, 2021
CVE-2020-23740
7.8

CVE-2020-23740 is a local privilege escalation vulnerability in DriverGenius driver update software. Attackers can exploit this vulnerability to eleva...

Dec 3, 2020
CVE-2026-24322
7.7

SAP Solution Tools Plug-In (ST-PI) contains an authorization bypass vulnerability where authenticated users can access sensitive information without p...

Feb 10, 2026

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,003 CVEs classified as CWE-862, with 217 rated critical and 820 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free