VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,748)

page 78 of 88
  • CVE-2020-1720LowMar 17, 2020
    risk 0.20cvss 3.1epss 0.01

    A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database…

  • CVE-2016-0373LowAug 30, 2018
    risk 0.20cvss 3.1epss 0.01

    IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.

  • CVE-2026-6570LowApr 19, 2026
    risk 0.18cvss 2.7epss 0.00

    A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely.…

  • CVE-2026-2733LowFeb 19, 2026
    risk 0.18cvss 3.8epss 0.00

    A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client “Enabled” setting to OFF does not fully prevent access.…

  • CVE-2025-12958LowJan 7, 2026
    risk 0.18cvss 2.7epss 0.00

    The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect capability check on the 'rankology_code_block' page in all versions up to, and including, 2.0. This makes it possible for authenticated attackers,…

  • CVE-2024-48921LowOct 29, 2024
    risk 0.18cvss 2.7epss 0.01

    Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. Administrators may not…

  • CVE-2024-30260LowApr 4, 2024
    risk 0.18cvss 3.9epss 0.01

    Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

  • CVE-2023-30954LowNov 15, 2023
    risk 0.18cvss 2.7epss 0.00

    The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized.

  • CVE-2020-24404LowNov 9, 2020
    risk 0.18cvss 2.7epss 0.02

    Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.

  • CVE-2020-24403LowNov 9, 2020
    risk 0.18cvss 2.7epss 0.02

    Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory…

  • CVE-2026-9306LowMay 23, 2026
    risk 0.17cvss 3.7epss 0.00

    A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The…

  • CVE-2024-46989LowSep 18, 2024
    risk 0.17cvss 3.7epss 0.00

    spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can result in no permission being returned when permission is…

  • CVE-2024-5798LowJun 12, 2024
    risk 0.17cvss 2.6epss 0.00

    Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audience and role-bound claims do not match, allowing an invalid login to succeed…

  • CVE-2021-3049LowSep 8, 2021
    risk 0.17cvss 2.6epss 0.00

    An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of. This issue…

  • CVE-2026-18283LowAug 20, 2026
    risk 0.16cvss 2.4epss 0.00

    Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2025-2397LowMar 17, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper…

  • CVE-2024-42036LowAug 8, 2024
    risk 0.16cvss 2.5epss 0.00

    Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-21454LowMar 16, 2023
    risk 0.16cvss 2.4epss 0.00

    Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.

  • CVE-2015-10033LowJan 9, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of the component Grade Handler. The manipulation leads to improper authorization. The identifier of the patch is 134f5481e2914b7f096cd92a22b1e6bcb8e6dfe5. It is…

  • CVE-2026-18817LowAug 4, 2026
    risk 0.14cvss 2.2epss 0.00

    A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. Performing a manipulation…