VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 75 of 82
  • CVE-2026-16195MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect authorization. It is possible to launch the…

  • CVE-2026-16126HigJul 18, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authorization. The attack is possible to be…

  • CVE-2026-16122MedJul 18, 2026
    risk 0.00cvss 4.3epss 0.00

    A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit…

  • CVE-2026-16121MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly…

  • CVE-2026-16119MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is…

  • CVE-2026-16075MedJul 18, 2026
    risk 0.00cvss 4.3epss 0.00

    A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. This manipulation of the argument Username causes…

  • CVE-2026-61718MedJul 16, 2026
    risk 0.00cvss 5.4epss 0.00

    bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ URL prefix, so routes in src/ui/app/routes/cache.py protected only by @login_required,…

  • CVE-2026-15909MedJul 16, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass. The attack is possible to be carried out…

  • CVE-2026-58540HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58277HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-54121HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50346HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50344HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58631HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

  • CVE-2026-49170HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.03

    Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

  • CVE-2026-15622MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.00

    A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack…

  • CVE-2026-15594LowJul 13, 2026
    risk 0.00cvss 3.7epss 0.00

    A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be…

  • CVE-2026-15516MedJul 13, 2026
    risk 0.00cvss 5.6epss 0.00

    A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The…

  • CVE-2026-15510MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was…

  • CVE-2026-15509MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been…