VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 180 of 475
  • CVE-2017-7677MedJun 14, 2017
    risk 0.39cvss 5.9epss 0.03

    In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.

  • CVE-2026-79208MedAug 25, 2026
    risk 0.38cvss 5.9epss 0.00

    Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-79652MedAug 25, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer…

  • CVE-2026-66595MedAug 20, 2026
    risk 0.38cvss 5.9epss 0.00

    Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.

  • CVE-2026-53966higAug 19, 2026
    risk 0.38cvss epss

    ### Impact Any user who can edit a page in XWiki can use Live Data's edit REST API in XWiki to change the rights on that page. This allows the user to obtain script right on the page. Script right allows the user to execute potentially dangerous Velocity scripts and send…

  • CVE-2026-67440MedAug 18, 2026
    risk 0.38cvss epss 0.00

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js return device-discovery, node-attribute, host-network-interface,…

  • CVE-2026-55178higAug 18, 2026
    risk 0.38cvss epss

    ### Summary Multiple GeoLens read/link endpoints authorized only the resource named in the request URL (a map, a VRT, a source dataset, an AI request) and failed to re-authorize a **second, caller-influenced dataset** that the request reached through a relationship, layer…

  • CVE-2026-73048MedAug 14, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifiers citing PDF annotations without publish-access filtering. Attackers can extract block identifiers from restricted documents by…

  • CVE-2026-73609MedAug 13, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark…

  • CVE-2026-73607MedAug 13, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authorization checks. Attackers can retrieve outline state including heading identifiers for any document by supplying its identifier,…

  • CVE-2026-73605MedAug 13, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. Attackers can supply arbitrary absolute paths to determine whether files and…

  • CVE-2026-72806MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when rendering attribute views and database rows. Unauthenticated readers can access password-protected document…

  • CVE-2026-72805MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata. Anonymous readers or publish RoleReader accounts can retrieve document titles,…

  • CVE-2026-72803MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and custom fields from protected documents by sending POST requests with block IDs.

  • CVE-2026-72800MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally,…

  • CVE-2026-72799MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when Publish.Auth.Enable is false, an unauthenticated…

  • CVE-2026-72797MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. Anonymous readers and publish-mode accounts can…

  • CVE-2026-72796MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforced on the REST API. Attackers with publish reader tokens or anonymous access in disabled-auth mode can read templates, snippets,…

  • CVE-2026-72791MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information disclosure vulnerability in the /api/av/getAttributeViewFieldViews endpoint. The route is registered with CheckAuth only and applies no publish-access…

  • CVE-2026-72790MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document counts, sizes, and timestamps for closed or non-published…