VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 13 of 82
  • CVE-2020-25716HigJun 7, 2021
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for…

  • CVE-2021-22863HigMar 3, 2021
    risk 0.53cvss 8.1epss 0.01

    An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance to modify the maintainer collaboration permission of a pull request without proper authorization. By exploiting this…

  • CVE-2021-21511HigFeb 15, 2021
    risk 0.53cvss 8.1epss 0.01

    Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could potentially exploit this vulnerability, to gain unauthorized read or modification access to other users' backup data.

  • CVE-2020-2050HigNov 12, 2020
    risk 0.53cvss 8.2epss 0.01

    An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authenticate as any user and…

  • CVE-2019-16328HigOct 3, 2019
    risk 0.53cvss 7.5epss 0.13

    In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.

  • CVE-2019-1863HigAug 21, 2019
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization…

  • CVE-2016-10859HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).

  • CVE-2019-3785HigMar 13, 2019
    risk 0.53cvss 8.1epss 0.01

    Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to…

  • CVE-2018-15465HigDec 24, 2018
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to…

  • CVE-2016-7143HigSep 21, 2016
    risk 0.53cvss 8.1epss 0.01

    The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

  • CVE-2026-73421CriAug 13, 2026
    risk 0.52cvss epss 0.01

    NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In…

  • CVE-2026-47298HigJun 9, 2026
    risk 0.52cvss 8.0epss 0.01

    Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-43515CriMay 12, 2026
    risk 0.52cvss 9.1epss 0.01

    Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0…

  • CVE-2026-27912HigApr 14, 2026
    risk 0.52cvss 8.0epss 0.00

    Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

  • CVE-2026-33186CriMar 20, 2026
    risk 0.52cvss 9.1epss 0.02

    gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path`…

  • CVE-2026-20960HigJan 16, 2026
    risk 0.52cvss 8.0epss 0.00

    Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

  • CVE-2024-45337CriDec 12, 2024
    risk 0.52cvss 9.1epss 0.03

    Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee…

  • CVE-2024-38821CriOct 28, 2024
    risk 0.52cvss 9.1epss 0.02

    Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: * It must be a WebFlux application * It must be using Spring's…

  • CVE-2023-50780HigOct 14, 2024
    risk 0.52cvss 8.8epss 0.17

    Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative…

  • CVE-2023-20186HigSep 27, 2023
    risk 0.52cvss 8.0epss 0.01

    A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using…