VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 427 of 464
  • CVE-2017-17807LowDec 20, 2017
    risk 0.21cvss 3.3epss 0.00

    The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing a local user to use a sequence of crafted system calls to add keys to a keyring…

  • CVE-2017-5985LowMar 14, 2017
    risk 0.21cvss 3.3epss 0.00

    lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.

  • CVE-2026-75850MedAug 18, 2026
    risk 0.20cvss 4.2epss 0.00

    ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers. Because no principal is bound on the worker thread, the engine's fine-grained per-type ACL layer (LocalBucket.checkPermissionsOnFile) does not execute…

  • CVE-2026-65926LowAug 12, 2026
    risk 0.20cvss 3.1epss 0.00

    An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.

  • CVE-2026-13236MedJul 10, 2026
    risk 0.20cvss 4.2epss 0.00

    Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.

  • CVE-2026-44991MedMay 11, 2026
    risk 0.20cvss 4.2epss 0.00

    OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are configured without explicit owner allowFrom settings. Attackers can exploit this…

  • CVE-2026-4590LowMar 23, 2026
    risk 0.20cvss 3.1epss 0.00

    A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /workspace/source-code/plugins/oauth/controller/bind/index.class.php of the component loginSubmit API. Performing a manipulation of the argument third results in…

  • CVE-2026-3193LowFeb 25, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. The manipulation results in cross-site request forgery. The attack may be performed from remote. The attack requires a high level of complexity. The…

  • CVE-2025-15289LowFeb 5, 2026
    risk 0.20cvss 3.1epss 0.00

    Tanium addressed an improper access controls vulnerability in Interact.

  • CVE-2026-1751LowFeb 2, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

  • CVE-2025-13643LowNov 25, 2025
    risk 0.20cvss 3.1epss 0.00

    A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB…

  • CVE-2025-12817LowNov 13, 2025
    risk 0.20cvss 3.1epss 0.00

    Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then…

  • CVE-2025-42914LowSep 9, 2025
    risk 0.20cvss 3.1epss 0.00

    Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the…

  • CVE-2025-42913LowSep 9, 2025
    risk 0.20cvss 3.1epss 0.00

    Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the…

  • CVE-2025-58460MedSep 3, 2025
    risk 0.20cvss 4.2epss 0.00

    A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…

  • CVE-2023-5600LowJun 20, 2025
    risk 0.20cvss 3.1epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked…

  • CVE-2025-48009LowMay 21, 2025
    risk 0.20cvss 3.1epss 0.00

    Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.

  • CVE-2024-55070LowMar 27, 2025
    risk 0.20cvss 3.1epss 0.00

    A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allows group managers to edit their own permissions.

  • CVE-2025-26655LowMar 11, 2025
    risk 0.20cvss 3.1epss 0.00

    SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are…

  • CVE-2024-10527LowJan 7, 2025
    risk 0.20cvss 3.1epss 0.00

    The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the motech_spacer_callback() function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level access…