VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 183 of 475
  • CVE-2020-4175MedAug 27, 2020
    risk 0.38cvss 5.9epss 0.02

    IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…

  • CVE-2020-4413MedJun 24, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…

  • CVE-2019-7272MedJul 1, 2019
    risk 0.38cvss 5.3epss 0.10

    Optergy Proton/Enterprise devices allow Username Disclosure.

  • CVE-2026-19017MedAug 7, 2026
    risk 0.37cvss 6.8epss 0.00

    Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul…

  • CVE-2026-44409MedMay 22, 2026
    risk 0.37cvss 5.7epss 0.00

    There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.

  • CVE-2025-65089MedNov 19, 2025
    risk 0.37cvss 6.8epss 0.00

    XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched…

  • CVE-2025-25244MedMar 11, 2025
    risk 0.37cvss 5.7epss 0.00

    SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding…

  • CVE-2024-0235MedJan 16, 2024
    risk 0.37cvss 5.3epss 0.38

    The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

  • CVE-2023-47870MedNov 30, 2023
    risk 0.37cvss 5.7epss 0.00

    Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a…

  • CVE-2023-26510MedMar 5, 2023
    risk 0.37cvss 5.7epss 0.01

    Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this…

  • CVE-2023-22488MedJan 12, 2023
    risk 0.37cvss 6.8epss 0.00

    Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification…

  • CVE-2022-39960MedSep 17, 2022
    risk 0.37cvss 5.3epss 0.26

    The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/…

  • CVE-2022-34212MedJun 23, 2022
    risk 0.37cvss 5.7epss 0.01

    A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.

  • CVE-2021-25011MedFeb 28, 2022
    risk 0.37cvss 5.7epss 0.00

    The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

  • CVE-2020-13938MedJun 10, 2021
    risk 0.37cvss 5.5epss 0.12

    Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows

  • CVE-2019-16097MedSep 8, 2019
    risk 0.37cvss 6.5epss 0.22

    core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without…

  • CVE-2026-61936MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-15248MedAug 2, 2026
    risk 0.36cvss 5.5epss 0.00

    The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.

  • CVE-2026-18201MedJul 29, 2026
    risk 0.36cvss 5.5epss 0.00

    Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions…

  • CVE-2026-44918MedJul 10, 2026
    risk 0.36cvss 5.5epss 0.00

    OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.