VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,439)

page 306 of 472
  • CVE-2026-40570MedApr 21, 2026
    risk 0.30cvss epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` returns complete customer profile data to any authenticated user without verifying mailbox access. An attacker only needs a valid…

  • CVE-2025-48614MedDec 8, 2025
    risk 0.30cvss 4.6epss 0.00

    In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permission check. This could lead to physical denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-54470MedJan 15, 2025
    risk 0.30cvss 4.6epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contacts from the lock screen.

  • CVE-2024-45461MedOct 16, 2024
    risk 0.30cvss 5.7epss 0.01

    The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments where the feature is enabled, due to missing access check enforcements, non-administrative CloudStack user…

  • CVE-2024-3097MedApr 9, 2024
    risk 0.30cvss 5.3epss 0.38

    The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract…

  • CVE-2023-35998MedJun 27, 2023
    risk 0.30cvss 4.6epss 0.00

    A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token.…

  • CVE-2023-2494MedMay 24, 2023
    risk 0.30cvss 4.6epss 0.00

    The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_postdata' function in versions up to, and including, 3.3.19. This makes it possible for authenticated…

  • CVE-2023-20064MedMar 9, 2023
    risk 0.30cvss 4.6epss 0.00

    A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line. This vulnerability is due to the inclusion…

  • CVE-2021-24968MedJan 24, 2022
    risk 0.30cvss 5.7epss 0.00

    The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ…

  • CVE-2021-1835MedSep 8, 2021
    risk 0.30cvss 4.6epss 0.00

    This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to access notes from the lock screen.

  • CVE-2020-13626MedOct 9, 2020
    risk 0.30cvss 4.6epss 0.00

    OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.

  • CVE-2026-79672MedAug 25, 2026
    risk 0.29cvss 5.5epss

    Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation operations. Attackers with a limited-scope access token can list, approve, reject, delete comments,…

  • CVE-2026-75982MedAug 25, 2026
    risk 0.29cvss 4.4epss 0.00

    The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in versions up to, and including, 4.4.4 via the learnpress_create_page AJAX action. The LP_Admin_Ajax::create_page() handler only checks the edit_pages capability and a…

  • CVE-2026-47718MedAug 12, 2026
    risk 0.29cvss epss 0.00

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.

  • CVE-2026-55628MedJul 1, 2026
    risk 0.29cvss 5.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy.…

  • CVE-2026-53850MedJun 16, 2026
    risk 0.29cvss 5.5epss 0.00

    OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command to change focus state outside intended…

  • CVE-2025-30017MedApr 8, 2025
    risk 0.29cvss 4.4epss 0.00

    Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.

  • CVE-2025-24116MedJan 27, 2025
    risk 0.29cvss 4.4epss 0.00

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to bypass Privacy preferences.

  • CVE-2024-40834MedJul 29, 2024
    risk 0.29cvss 4.4epss 0.00

    This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able to bypass sensitive Shortcuts app settings.

  • CVE-2023-48339MedJan 18, 2024
    risk 0.29cvss 4.4epss 0.00

    In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed