VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,748)

page 80 of 88
  • CVE-2026-43792MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.

  • CVE-2026-43775MedJul 27, 2026
    risk 0.00cvss 5.5epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

  • CVE-2026-43756MedJul 27, 2026
    risk 0.00cvss 5.5epss 0.00

    A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.

  • CVE-2026-17531MedJul 27, 2026
    risk 0.00cvss 5.0epss 0.00

    A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the…

  • CVE-2026-17530MedJul 27, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization.…

  • CVE-2026-17529MedJul 27, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is…

  • CVE-2026-17434MedJul 26, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The…

  • CVE-2026-17433MedJul 26, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to…

  • CVE-2026-62835CriJul 24, 2026
    risk 0.00cvss 9.3epss 0.01

    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-62444MedJul 21, 2026
    risk 0.00cvss 6.1epss 0.00

    Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-60886HigJul 21, 2026
    risk 0.00cvss 7.6epss 0.00

    Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-60152MedJul 21, 2026
    risk 0.00cvss 5.4epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-28312CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.

  • CVE-2026-16450MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to…

  • CVE-2026-34239HigJul 20, 2026
    risk 0.00cvss —epss 0.00

    Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`, which means any authenticated user enrolled in a course (student, teacher,…

  • CVE-2026-32821HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user who has their own access…

  • CVE-2026-32819MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard user can enumerate other users' names…

  • CVE-2026-32806HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary…

  • CVE-2026-32807HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, anyone with a DataLink UUID can fetch the attached…

  • CVE-2026-27823HigJul 20, 2026
    risk 0.00cvss —epss 0.01

    A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior…