VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 387 of 464
  • CVE-2019-10312MedApr 30, 2019
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doFillTowerCredentialsIdItems method allowed attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2019-3886MedApr 4, 2019
    risk 0.28cvss 5.4epss 0.01

    An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.

  • CVE-2019-5779MedFeb 19, 2019
    risk 0.28cvss 4.3epss 0.03

    Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2018-20155MedDec 14, 2018
    risk 0.28cvss 4.3epss 0.01

    The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.

  • CVE-2018-1314MedNov 8, 2018
    risk 0.28cvss 4.3epss 0.02

    In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.

  • CVE-2017-18035MedFeb 2, 2018
    risk 0.28cvss 4.3epss 0.01

    The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence…

  • CVE-2017-1000390MedJan 26, 2018
    risk 0.28cvss 4.3epss 0.01

    Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build.

  • CVE-2017-1000388MedJan 26, 2018
    risk 0.28cvss 4.3epss 0.01

    Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modify this data.

  • CVE-2017-17693MedDec 15, 2017
    risk 0.28cvss 4.3epss 0.01

    Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback.

  • CVE-2017-1000243MedNov 1, 2017
    risk 0.28cvss 4.3epss 0.01

    Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites

  • CVE-2026-65959MedAug 18, 2026
    risk 0.27cvss 5.3epss 0.00

    Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() without acl.CheckAccessHTTP(r,…

  • CVE-2026-53960MedAug 17, 2026
    risk 0.27cvss 5.3epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data, exposing it to any unauthenticated…

  • CVE-2026-73405MedAug 12, 2026
    risk 0.27cvss epss 0.00

    An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/ endpoint. The token_required decorator used by the Pub/Sub interface authenticated…

  • CVE-2026-73155MedAug 11, 2026
    risk 0.27cvss epss 0.00

    Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users are authorized to view the target comment. The vulnerable react() handler passed an attacker-controlled comment_id directly to…

  • CVE-2026-73140MedAug 11, 2026
    risk 0.27cvss epss 0.00

    Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversion visibility, comment privacy, ownership, authorship, and administrative…

  • CVE-2026-58241MedAug 11, 2026
    risk 0.27cvss 4.2epss 0.00

    SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects during specific operations. These unauthorized modifications could result in…

  • CVE-2026-72723MedAug 10, 2026
    risk 0.27cvss 5.3epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_menu_tags serializes tags from SiteSetting.default_navigation_menu_tags without applying DiscourseTagging.filter_visible for the…

  • CVE-2026-66058MedAug 7, 2026
    risk 0.27cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.

  • CVE-2026-66699MedAug 6, 2026
    risk 0.27cvss 5.3epss 0.00

    Custom role Broken Access Control in Dokan <= 5.0.10 versions.

  • CVE-2026-70435MedAug 5, 2026
    risk 0.27cvss 4.2epss 0.00

    A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.