VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 65 of 82
  • CVE-2023-0914MedFeb 19, 2023
    risk 0.27cvss 5.3epss 0.01

    Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4.

  • CVE-2023-21432MedFeb 9, 2023
    risk 0.27cvss 4.2epss 0.00

    Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.

  • CVE-2022-4804MedDec 28, 2022
    risk 0.27cvss 5.3epss 0.01

    Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2026-49446medJul 28, 2026
    risk 0.26cvss epss

    ### Summary The Constellation-tunnel bypass branch in `tokenMiddleware` at `src/proxy/routerGen.go:53-66` returns to the upstream handler before the request's `x-cosmos-user`, `x-cosmos-role`, `x-cosmos-user-role`, and `x-cosmos-mfa` headers are stripped at lines 68-72, and…

  • CVE-2026-52826medJul 14, 2026
    risk 0.26cvss epss

    ### Summary Kimai 2.56.0 contains an authenticated improper authorization vulnerability in the Web rate editing flows for projects, customers, and activities. A user who can edit one authorized parent object can combine that authorized parent ID with the rate ID of a different,…

  • CVE-2026-52825medJul 14, 2026
    risk 0.26cvss epss

    ### Summary Kimai contains an authenticated improper authorization vulnerability in Team-related assignment APIs. A Teamlead who can edit their own team can use backend API endpoints to add users or activities that fall outside their intended visible or manageable scope, even…

  • CVE-2026-52822medJul 14, 2026
    risk 0.26cvss epss

    ### Summary Kimai 2.56.0 contains an authenticated authorization bypass in the timesheet `restart` and `duplicate` workflows. After a user loses access to a project, the user can still derive a new timesheet from one of their historical entries and create a new record under…

  • CVE-2026-49463medJul 8, 2026
    risk 0.26cvss epss

    ## Impact In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user: - **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who…

  • CVE-2026-48717medJun 29, 2026
    risk 0.26cvss epss

    ## Summary **Description** An Improper Authorization (CWE-285) issue in OpenAM's OAuth2 authorization-code grant allows a PKCE-protected authorization code to be redeemed without the required code_verifier. This affects OpenAM Community Edition through version 16.0.6 and was…

  • CVE-2026-12771MedJun 21, 2026
    risk 0.26cvss 5.0epss 0.00

    A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high…

  • CVE-2026-11500MedJun 8, 2026
    risk 0.26cvss 5.0epss 0.00

    A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization…

  • CVE-2025-66406MedDec 3, 2025
    risk 0.26cvss 5.0epss 0.00

    Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is…

  • CVE-2025-3454MedJun 2, 2025
    risk 0.26cvss 5.0epss 0.00

    This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. …

  • CVE-2023-42973MedApr 11, 2025
    risk 0.26cvss 4.0epss 0.00

    Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI.

  • CVE-2023-42541MedNov 7, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.

  • CVE-2023-21505MedMay 4, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox.

  • CVE-2023-21461MedMar 16, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.

  • CVE-2023-21429MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.

  • CVE-2022-39905MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.

  • CVE-2022-39883MedNov 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.