← Vulnerability feed

Vulnerability record · CVE-2020-14106 · published 8 April 2021

CVE-2020-14106: Miui incorrect authorization vulnerability

MMi · Miui

The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26.

5.5 CVSS 3.1 Medium EPSS 0.66% · top 50.3% CWE-863 · Incorrect authorization
5.5CVSS 3.1 base score, v2 4.3
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-14106 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-14120Miui vulnerabilitySome Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party applic…EPSS 0.42%7.5CVE-2020-14127Miui out-of-bounds write vulnerabilityA denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attack…EPSS 1.0%7.5CVE-2020-14125Miui out-of-bounds read vulnerabilityA denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited…EPSS 7.3%7.5CVE-2020-14123Miui double free vulnerabilityThere is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, …EPSS 0.93%5.5CVE-2020-14122Miui insufficient verification of data authenticity vulnerabilitySome Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter v…EPSS 0.16%5.5CVE-2020-14105Miui vulnerabilityThe application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.EPSS 0.26%5.5CVE-2020-14103Miui vulnerabilityThe application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.EPSS 0.70%9.1CVE-2026-71362Adobe commerce incorrect authorization vulnerabilityAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…KEVEPSS 88%

Source: NIST National Vulnerability Database (record CVE-2020-14106), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.