CWE-285
Improper Authorization
Description
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87
CVEs mapped to this weakness (1,626)
page 75 of 82| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-16195 | Med | 0.00 | 6.3 | 0.00 | Jul 18, 2026 | A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect authorization. It is possible to launch the… | ||
| CVE-2026-16126 | Hig | 0.00 | 7.3 | 0.00 | Jul 18, 2026 | A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authorization. The attack is possible to be… | ||
| CVE-2026-16122 | Med | 0.00 | 4.3 | 0.00 | Jul 18, 2026 | A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit… | ||
| CVE-2026-16121 | Med | 0.00 | 6.3 | 0.00 | Jul 18, 2026 | A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly… | ||
| CVE-2026-16119 | Med | 0.00 | 6.3 | 0.00 | Jul 18, 2026 | A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is… | ||
| CVE-2026-16075 | Med | 0.00 | 4.3 | 0.00 | Jul 18, 2026 | A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. This manipulation of the argument Username causes… | ||
| CVE-2026-61718 | Med | 0.00 | 5.4 | 0.00 | Jul 16, 2026 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ URL prefix, so routes in src/ui/app/routes/cache.py protected only by @login_required,… | ||
| CVE-2026-15909 | Med | 0.00 | 6.3 | 0.00 | Jul 16, 2026 | A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass. The attack is possible to be carried out… | ||
| CVE-2026-58540 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-58277 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-54121 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-50346 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50344 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-58631 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. | ||
| CVE-2026-49170 | Hig | 0.00 | 7.8 | 0.03 | Jul 14, 2026 | Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-15622 | Med | 0.00 | 5.3 | 0.00 | Jul 14, 2026 | A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack… | ||
| CVE-2026-15594 | Low | 0.00 | 3.7 | 0.00 | Jul 13, 2026 | A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be… | ||
| CVE-2026-15516 | Med | 0.00 | 5.6 | 0.00 | Jul 13, 2026 | A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The… | ||
| CVE-2026-15510 | Med | 0.00 | 6.3 | 0.00 | Jul 12, 2026 | A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was… | ||
| CVE-2026-15509 | Med | 0.00 | 6.3 | 0.00 | Jul 12, 2026 | A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been… |
- risk 0.00cvss 6.3epss 0.00
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect authorization. It is possible to launch the…
- risk 0.00cvss 7.3epss 0.00
A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authorization. The attack is possible to be…
- risk 0.00cvss 4.3epss 0.00
A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is…
- risk 0.00cvss 4.3epss 0.00
A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. This manipulation of the argument Username causes…
- risk 0.00cvss 5.4epss 0.00
bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ URL prefix, so routes in src/ui/app/routes/cache.py protected only by @login_required,…
- risk 0.00cvss 6.3epss 0.00
A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass. The attack is possible to be carried out…
- risk 0.00cvss 7.8epss 0.00
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.01
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 8.8epss 0.01
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 7.8epss 0.00
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.03
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.3epss 0.00
A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack…
- risk 0.00cvss 3.7epss 0.00
A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be…
- risk 0.00cvss 5.6epss 0.00
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was…
- risk 0.00cvss 6.3epss 0.00
A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been…