VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 2 of 82
  • CVE-2025-63218CriNov 19, 2025
    risk 0.64cvss 9.8epss 0.01

    The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative…

  • CVE-2025-31255CriSep 15, 2025
    risk 0.64cvss 9.8epss 0.02

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be able to access sensitive user data.

  • CVE-2025-7778CriAug 15, 2025
    risk 0.64cvss 9.8epss 0.01

    The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it possible for unauthenticated attackers to…

  • CVE-2025-49746CriJul 18, 2025
    risk 0.64cvss 9.9epss 0.01

    Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-4631CriMay 31, 2025
    risk 0.64cvss 9.8epss 0.01

    The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. This makes it possible to trigger the save_object_as_user() function for objects whose '_datatype' is set…

  • CVE-2025-29827CriMay 8, 2025
    risk 0.64cvss 9.9epss 0.01

    Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-3918CriMay 3, 2025
    risk 0.64cvss 9.8epss 0.01

    The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration handler reads the client-supplied $_POST['user_role'] and passes it directly to…

  • CVE-2025-30392CriApr 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-30390CriApr 30, 2025
    risk 0.64cvss 9.9epss 0.01

    Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-29659CriApr 21, 2025
    risk 0.64cvss 9.8epss 0.01

    Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.

  • CVE-2025-2345CriMar 16, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. This affects an unknown part. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The vendor was contacted early…

  • CVE-2024-56323CriJan 13, 2025
    risk 0.64cvss 9.8epss 0.00

    OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObjects with a model that uses…

  • CVE-2024-36130CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.02

    An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.

  • CVE-2024-28285CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.

  • CVE-2024-34257CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.

  • CVE-2024-24830CriFeb 8, 2024
    risk 0.64cvss 9.9epss 0.01

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to…

  • CVE-2022-3748CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.

  • CVE-2023-1782CriApr 5, 2023
    risk 0.64cvss 9.9epss 0.01

    HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.

  • CVE-2022-2661CriAug 16, 2022
    risk 0.64cvss 9.9epss 0.01

    Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using specifically crafted requests.

  • CVE-2022-24083CriJul 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.