VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,439)

page 304 of 472
  • CVE-2024-39824MedAug 14, 2024
    risk 0.32cvss 4.9epss 0.01

    Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

  • CVE-2024-39823MedAug 14, 2024
    risk 0.32cvss 4.9epss 0.00

    Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

  • CVE-2024-22272MedJun 27, 2024
    risk 0.32cvss 4.9epss 0.00

    VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator for a given organization within VMware Cloud Director may be able to accidentally disable their organization leading to a Denial of Service for active…

  • CVE-2023-37492MedAug 8, 2023
    risk 0.32cvss 4.9epss 0.00

    SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 793,…

  • CVE-2023-0805MedMay 3, 2023
    risk 0.32cvss 4.9epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a…

  • CVE-2021-32503MedApr 1, 2022
    risk 0.32cvss 4.9epss 0.01

    Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.

  • CVE-2020-19890MedAug 24, 2020
    risk 0.32cvss 4.9epss 0.01

    DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.

  • CVE-2026-76876MedAug 21, 2026
    risk 0.31cvss 5.9epss 0.00

    Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the Settings resource. Attackers can send a GET request to the settings API endpoint…

  • CVE-2026-50550MedAug 19, 2026
    risk 0.31cvss 5.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint authorizes update access but does not…

  • CVE-2026-58432MedAug 13, 2026
    risk 0.31cvss 5.9epss 0.00

    Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea

  • CVE-2026-57886MedAug 13, 2026
    risk 0.31cvss 5.9epss 0.00

    Cross-repository issue/comment attachment re-linking can expose private attachment content

  • CVE-2026-72808MedAug 12, 2026
    risk 0.31cvss 5.8epss 0.00

    SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint, which returns .sya PDF-annotation file content without a publish-access check. Because the endpoint is gated only by…

  • CVE-2026-71959MedAug 10, 2026
    risk 0.31cvss 5.8epss 0.00

    Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log.

  • CVE-2026-15060MedAug 10, 2026
    risk 0.31cvss 4.7epss 0.00

    When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259…

  • CVE-2026-68585MedAug 3, 2026
    risk 0.31cvss 5.8epss 0.00

    SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. Anonymous readers or publish RoleReader tokens can…

  • CVE-2026-44595MedJul 16, 2026
    risk 0.31cvss 4.3epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any…

  • CVE-2026-39595MedJun 17, 2026
    risk 0.31cvss 4.7epss 0.00

    Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.

  • CVE-2026-42320MedJun 3, 2026
    risk 0.31cvss epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.

  • CVE-2026-44448MedMay 13, 2026
    risk 0.31cvss 5.9epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 15.102.0 and 16.11.0.

  • CVE-2026-6663MedMay 12, 2026
    risk 0.31cvss 4.8epss 0.00

    The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints (gwd-backup.php and gwd-logs.php) not verifying authentication when the API key…