VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 4 of 82
  • CVE-2025-20125CriFeb 5, 2025
    risk 0.63cvss 9.1epss 0.17

    A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and…

  • CVE-2026-33823CriMay 7, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

  • CVE-2025-63691CriNov 7, 2025
    risk 0.62cvss 9.6epss 0.00

    In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/admin/sys-token/page) has an improper permission verification issue, which leads to information leakage. This interface can be…

  • CVE-2024-45387CriDec 23, 2024
    risk 0.61cvss 9.9epss 0.42

    An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. …

  • CVE-2021-3616CriAug 17, 2021
    risk 0.61cvss 9.4epss 0.01

    A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter firmware content and device configuration. This vulnerability is the same as CNVD-2020-68651.

  • CVE-2017-11398HigJan 19, 2018
    risk 0.61cvss 8.8epss 0.08

    A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an unauthenticated attacker to hijack active user sessions to perform authenticated requests on a vulnerable system.

  • CVE-2026-59118CriAug 7, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-18367CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.

  • CVE-2026-24305CriJan 22, 2026
    risk 0.60cvss 9.3epss 0.01

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2025-24434CriFeb 11, 2025
    risk 0.60cvss 9.1epss 0.17

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain…

  • CVE-2026-56160CriJul 24, 2026
    risk 0.59cvss 9.1epss 0.01

    Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-55166criJun 25, 2026
    risk 0.59cvss epss

    <!-- obsidian -->Lemur 1.9.0: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access…

  • CVE-2026-45052criJun 24, 2026
    risk 0.59cvss epss

    ## Summary **Description** An Improper Authorization (CWE-285) issue in OpenAM's Liberty Web Services SOAP receiver allows an unauthenticated remote attacker to write persistent entries into the Liberty Discovery store on any user's LDAP entry, and into a shared root-realm…

  • CVE-2026-48579CriJun 4, 2026
    risk 0.59cvss 9.1epss 0.01

    Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-66301CriDec 1, 2025
    risk 0.59cvss 9.6epss 0.01

    Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the form is now able to change the functioning…

  • CVE-2025-65021CriNov 19, 2025
    risk 0.59cvss 9.1epss 0.00

    Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists in the poll finalization feature of the application. Any authenticated user can finalize a poll they do not own by manipulating the…

  • CVE-2025-53795CriAug 21, 2025
    risk 0.59cvss 9.1epss 0.01

    Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-53792CriAug 7, 2025
    risk 0.59cvss 9.1epss 0.01

    Azure Portal Elevation of Privilege Vulnerability

  • CVE-2024-13241CriJan 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5.

  • CVE-2024-33749CriMay 6, 2024
    risk 0.59cvss 9.1epss 0.01

    DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.