VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 74 of 82
  • CVE-2026-17433MedJul 26, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to…

  • CVE-2026-62835CriJul 24, 2026
    risk 0.00cvss 9.3epss 0.01

    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-62444MedJul 21, 2026
    risk 0.00cvss 6.1epss 0.00

    Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-61082MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2026-60886HigJul 21, 2026
    risk 0.00cvss 7.6epss 0.00

    Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-60152MedJul 21, 2026
    risk 0.00cvss 5.4epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-28312CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.

  • CVE-2026-16450MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to…

  • CVE-2026-34239HigJul 20, 2026
    risk 0.00cvss epss 0.00

    Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`, which means any authenticated user enrolled in a course (student, teacher,…

  • CVE-2026-32821HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user who has their own access…

  • CVE-2026-32819MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard user can enumerate other users' names…

  • CVE-2026-32806HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary…

  • CVE-2026-32807HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, anyone with a DataLink UUID can fetch the attached…

  • CVE-2026-27823HigJul 20, 2026
    risk 0.00cvss epss 0.01

    A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior…

  • CVE-2026-63752MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission. Attackers can issue a RELATE statement with a SET id clause pointing…

  • CVE-2026-16224MedJul 19, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The…

  • CVE-2026-16217MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the argument project_id leads to authorization…

  • CVE-2026-16214MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be executed remotely. The exploit is…

  • CVE-2026-16200HigJul 19, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The manipulation leads to incorrect authorization. Remote exploitation of the attack is possible. The…

  • CVE-2026-16199MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit…