VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 399 of 464
  • CVE-2020-15247MedNov 23, 2020
    risk 0.27cvss 5.2epss 0.00

    October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.469, an authenticated backend user with the cms.manage_pages, cms.manage_layouts, or cms.manage_partials permissions who would…

  • CVE-2020-13464MedAug 31, 2020
    risk 0.27cvss 4.2epss 0.00

    The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU or DMA module.

  • CVE-2019-0325MedJul 10, 2019
    risk 0.27cvss 4.2epss 0.01

    SAP ERP HCM (SAP_HRCES) , version 3, does not perform necessary authorization checks for a report that reads payroll data of employees in a certain area. Due to this under certain conditions, the user that once had authorization to payroll data of an employee, which was later…

  • CVE-2026-64866MedAug 17, 2026
    risk 0.26cvss epss 0.00

    New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE /api/user/:id/reset_passkey, allowing a…

  • CVE-2026-11876MedJul 21, 2026
    risk 0.26cvss 5.0epss 0.00

    In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all users and tenants. This includes stack component…

  • CVE-2026-53718medJul 16, 2026
    risk 0.26cvss epss

    ### Impact Envoy Gateway accepts extension-managed custom backendRefs from an HTTPRoute to a backend resource in another namespace without requiring a matching Gateway API ReferenceGrant in the target namespace. This breaks the Gateway API cross-namespace consent model: the…

  • CVE-2026-52828medJul 14, 2026
    risk 0.26cvss epss

    ### Summary The `ExportController` web routes for creating and editing export templates are gated only by the class-level `create_export` permission, which is granted to `ROLE_TEAMLEAD` by default. The corresponding API routes and UI button visibility correctly require the…

  • CVE-2026-52825medJul 14, 2026
    risk 0.26cvss epss

    ### Summary Kimai contains an authenticated improper authorization vulnerability in Team-related assignment APIs. A Teamlead who can edit their own team can use backend API endpoints to add users or activities that fall outside their intended visible or manageable scope, even…

  • CVE-2026-52822medJul 14, 2026
    risk 0.26cvss epss

    ### Summary Kimai 2.56.0 contains an authenticated authorization bypass in the timesheet `restart` and `duplicate` workflows. After a user loses access to a project, the user can still derive a new timesheet from one of their historical entries and create a new record under…

  • CVE-2026-52821medJul 14, 2026
    risk 0.26cvss epss

    ### Summary Kimai 2.56.0 contains an authenticated improper authorization vulnerability in the preset-project activity creation flow. A user with the generic `create_activity` permission, but without access to a target project, can still create a new `Activity` under that…

  • CVE-2026-57221MedJul 10, 2026
    risk 0.26cvss 5.0epss 0.00

    RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to…

  • CVE-2026-53769medJul 9, 2026
    risk 0.26cvss epss

    ### Summary Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as `upload_{FIELD_ID}?`. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add…

  • CVE-2026-53602medJul 9, 2026
    risk 0.26cvss epss

    ## Summary Two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate *issuance* time — only at poll time. ## 1. Blocklist not…

  • CVE-2026-55863medJun 23, 2026
    risk 0.26cvss epss

    ## Summary The `ActionHandler.post()` method in motionEye has no authentication decorator, allowing any unauthenticated attacker to trigger camera actions including snapshots, recording start/stop, and configured action scripts (PTZ controls, alarm triggers, etc.). ##…

  • CVE-2026-44550MedMay 15, 2026
    risk 0.26cvss 5.0epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = ConfigDict(extra='allow'), which permits arbitrary fields to pass through Pydantic validation and be included in…

  • CVE-2026-0024MedMar 2, 2026
    risk 0.26cvss 4.0epss 0.00

    In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2026-27111MedFeb 20, 2026
    risk 0.26cvss 5.0epss 0.00

    Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model includes a promote verb -- a non-standard Kubernetes "dolphin verb" -- that gates the ability to advance Freight through a promotion pipeline. This verb exists to…

  • CVE-2025-43331MedSep 15, 2025
    risk 0.26cvss 4.0epss 0.00

    A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access protected user data.

  • CVE-2025-8285MedAug 11, 2025
    risk 0.26cvss 4.0epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.

  • CVE-2025-53910MedAug 11, 2025
    risk 0.26cvss 4.0epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.