VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 104 of 464
  • CVE-2018-15327HigOct 31, 2018
    risk 0.47cvss 7.2epss 0.01

    In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be…

  • CVE-2009-3168HigSep 11, 2009
    risk 0.47cvss 7.2epss 0.03

    Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request.

  • CVE-2026-71308HigAug 18, 2026
    risk 0.46cvss 8.1epss 0.00

    Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a CertificatePermission check. Assigning those…

  • CVE-2026-75846HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a server-side function without any checkPermissionsOnDatabase…

  • CVE-2026-75109HigAug 17, 2026
    risk 0.46cvss 7.1epss 0.00

    Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own.

  • CVE-2026-73658HigAug 13, 2026
    risk 0.46cvss 8.2epss 0.00

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname,…

  • CVE-2026-72675HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a…

  • CVE-2026-28173HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.

  • CVE-2026-27535HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.

  • CVE-2026-16494HigAug 12, 2026
    risk 0.46cvss 7.1epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization…

  • CVE-2026-64954HigAug 12, 2026
    risk 0.46cvss 8.2epss 0.00

    Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows…

  • CVE-2026-48763HigAug 11, 2026
    risk 0.46cvss 8.2epss 0.00

    TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact…

  • CVE-2026-47765HigAug 6, 2026
    risk 0.46cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This…

  • CVE-2026-18277HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the…

  • CVE-2026-66470HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.

  • CVE-2026-65554HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.

  • CVE-2026-70617HigAug 5, 2026
    risk 0.46cvss 8.1epss 0.00

    Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can…

  • CVE-2026-70494HigAug 4, 2026
    risk 0.46cvss 8.1epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete…

  • CVE-2026-13227HigAug 4, 2026
    risk 0.46cvss epss 0.00

    An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0.

  • CVE-2026-13229HigAug 4, 2026
    risk 0.46cvss epss 0.00

    Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.