VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,749)

page 82 of 88
  • CVE-2026-58631HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

  • CVE-2026-49170HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

  • CVE-2026-15622MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack…

  • CVE-2026-15594LowJul 13, 2026
    risk 0.00cvss 3.7epss 0.00

    A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be…

  • CVE-2026-15516MedJul 13, 2026
    risk 0.00cvss 5.6epss 0.00

    A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The…

  • CVE-2026-15510MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was…

  • CVE-2026-15509MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-56313HigJul 12, 2026
    risk 0.00cvss 8.1epss 0.01

    Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_settings permission and an active SSO…

  • CVE-2026-56241HigJul 12, 2026
    risk 0.00cvss 8.3epss 0.00

    Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared during role binding deletion.…

  • CVE-2026-15499MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of the file astrbot/core/tools/cron_tools.py of the component Scheduled Task Handler. Performing a manipulation of the argument payload["note"] results in…

  • CVE-2026-15474MedJul 12, 2026
    risk 0.00cvss 4.3epss 0.00

    A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file /callrec/audio.jsp of the component Call Recording Handler. The manipulation of the argument callId results in improper authorization. The attack may be…

  • CVE-2026-15473MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authorization. The attack is possible to be…

  • CVE-2026-15472MedJul 12, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been…

  • CVE-2026-15471MedJul 12, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been made public…

  • CVE-2026-15470MedJul 12, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to…

  • CVE-2026-56240MedJul 11, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid…

  • CVE-2026-55664MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table and column metadata without applying the document's access rules and did not check that the requested section was actually a form. A user with only partial…

  • CVE-2026-15377MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-15376MedJul 10, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could…

  • CVE-2026-15375MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /callrec/users_ldap.jsp of the component LDAP User Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit…