CWE-285
Improper Authorization
Description
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87
CVEs mapped to this weakness (1,626)
page 65 of 82| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0914 | Med | 0.27 | 5.3 | 0.01 | Feb 19, 2023 | Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4. | ||
| CVE-2023-21432 | Med | 0.27 | 4.2 | 0.00 | Feb 9, 2023 | Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner. | ||
| CVE-2022-4804 | Med | 0.27 | 5.3 | 0.01 | Dec 28, 2022 | Improper Authorization in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2026-49446 | med | 0.26 | — | — | Jul 28, 2026 | ### Summary The Constellation-tunnel bypass branch in `tokenMiddleware` at `src/proxy/routerGen.go:53-66` returns to the upstream handler before the request's `x-cosmos-user`, `x-cosmos-role`, `x-cosmos-user-role`, and `x-cosmos-mfa` headers are stripped at lines 68-72, and… | ||
| CVE-2026-52826 | med | 0.26 | — | — | Jul 14, 2026 | ### Summary Kimai 2.56.0 contains an authenticated improper authorization vulnerability in the Web rate editing flows for projects, customers, and activities. A user who can edit one authorized parent object can combine that authorized parent ID with the rate ID of a different,… | ||
| CVE-2026-52825 | med | 0.26 | — | — | Jul 14, 2026 | ### Summary Kimai contains an authenticated improper authorization vulnerability in Team-related assignment APIs. A Teamlead who can edit their own team can use backend API endpoints to add users or activities that fall outside their intended visible or manageable scope, even… | ||
| CVE-2026-52822 | med | 0.26 | — | — | Jul 14, 2026 | ### Summary Kimai 2.56.0 contains an authenticated authorization bypass in the timesheet `restart` and `duplicate` workflows. After a user loses access to a project, the user can still derive a new timesheet from one of their historical entries and create a new record under… | ||
| CVE-2026-49463 | med | 0.26 | — | — | Jul 8, 2026 | ## Impact In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user: - **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who… | ||
| CVE-2026-48717 | med | 0.26 | — | — | Jun 29, 2026 | ## Summary **Description** An Improper Authorization (CWE-285) issue in OpenAM's OAuth2 authorization-code grant allows a PKCE-protected authorization code to be redeemed without the required code_verifier. This affects OpenAM Community Edition through version 16.0.6 and was… | ||
| CVE-2026-12771 | Med | 0.26 | 5.0 | 0.00 | Jun 21, 2026 | A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high… | ||
| CVE-2026-11500 | Med | 0.26 | 5.0 | 0.00 | Jun 8, 2026 | A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization… | ||
| CVE-2025-66406 | Med | 0.26 | 5.0 | 0.00 | Dec 3, 2025 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is… | ||
| CVE-2025-3454 | Med | 0.26 | 5.0 | 0.00 | Jun 2, 2025 | This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. … | ||
| CVE-2023-42973 | Med | 0.26 | 4.0 | 0.00 | Apr 11, 2025 | Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI. | ||
| CVE-2023-42541 | Med | 0.26 | 4.0 | 0.00 | Nov 7, 2023 | Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id. | ||
| CVE-2023-21505 | Med | 0.26 | 4.0 | 0.00 | May 4, 2023 | Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox. | ||
| CVE-2023-21461 | Med | 0.26 | 4.0 | 0.00 | Mar 16, 2023 | Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity. | ||
| CVE-2023-21429 | Med | 0.26 | 4.0 | 0.00 | Feb 9, 2023 | Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID. | ||
| CVE-2022-39905 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent. | ||
| CVE-2022-39883 | Med | 0.26 | 4.0 | 0.00 | Nov 9, 2022 | Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API. |
- risk 0.27cvss 5.3epss 0.01
Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4.
- risk 0.27cvss 4.2epss 0.00
Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.
- risk 0.27cvss 5.3epss 0.01
Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.26cvss —epss —
### Summary The Constellation-tunnel bypass branch in `tokenMiddleware` at `src/proxy/routerGen.go:53-66` returns to the upstream handler before the request's `x-cosmos-user`, `x-cosmos-role`, `x-cosmos-user-role`, and `x-cosmos-mfa` headers are stripped at lines 68-72, and…
- risk 0.26cvss —epss —
### Summary Kimai 2.56.0 contains an authenticated improper authorization vulnerability in the Web rate editing flows for projects, customers, and activities. A user who can edit one authorized parent object can combine that authorized parent ID with the rate ID of a different,…
- risk 0.26cvss —epss —
### Summary Kimai contains an authenticated improper authorization vulnerability in Team-related assignment APIs. A Teamlead who can edit their own team can use backend API endpoints to add users or activities that fall outside their intended visible or manageable scope, even…
- risk 0.26cvss —epss —
### Summary Kimai 2.56.0 contains an authenticated authorization bypass in the timesheet `restart` and `duplicate` workflows. After a user loses access to a project, the user can still derive a new timesheet from one of their historical entries and create a new record under…
- risk 0.26cvss —epss —
## Impact In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user: - **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who…
- risk 0.26cvss —epss —
## Summary **Description** An Improper Authorization (CWE-285) issue in OpenAM's OAuth2 authorization-code grant allows a PKCE-protected authorization code to be redeemed without the required code_verifier. This affects OpenAM Community Edition through version 16.0.6 and was…
- risk 0.26cvss 5.0epss 0.00
A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high…
- risk 0.26cvss 5.0epss 0.00
A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization…
- risk 0.26cvss 5.0epss 0.00
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is…
- risk 0.26cvss 5.0epss 0.00
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. …
- risk 0.26cvss 4.0epss 0.00
Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI.
- risk 0.26cvss 4.0epss 0.00
Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.
- risk 0.26cvss 4.0epss 0.00
Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox.
- risk 0.26cvss 4.0epss 0.00
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
- risk 0.26cvss 4.0epss 0.00
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
- risk 0.26cvss 4.0epss 0.00
Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.
- risk 0.26cvss 4.0epss 0.00
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.