VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 428 of 464
  • CVE-2023-23825LowDec 9, 2024
    risk 0.20cvss 3.1epss 0.01

    Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.

  • CVE-2024-54153LowDec 4, 2024
    risk 0.20cvss 3.1epss 0.00

    In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

  • CVE-2024-5770MedJun 8, 2024
    risk 0.20cvss 4.2epss 0.00

    The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_setting' function in versions up to, and including, 1.66. This makes it possible for authenticated attackers,…

  • CVE-2024-4317LowMay 14, 2024
    risk 0.20cvss 3.1epss 0.01

    Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the…

  • CVE-2024-3932LowApr 18, 2024
    risk 0.20cvss 3.1epss 0.00

    A vulnerability classified as problematic has been found in Totara LMS up to 18.7. This affects an unknown part of the component User Selector. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The complexity of an attack is…

  • CVE-2023-22676LowDec 29, 2023
    risk 0.20cvss 3.1epss 0.00

    Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12.

  • CVE-2023-2233LowSep 29, 2023
    risk 0.20cvss 3.1epss 0.00

    An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry…

  • CVE-2023-4302MedAug 21, 2023
    risk 0.20cvss 4.2epss 0.00

    A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2023-4105LowAug 11, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message

  • CVE-2023-23344LowJun 23, 2023
    risk 0.20cvss 3.0epss 0.00

    A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.

  • CVE-2023-27462LowMar 14, 2023
    risk 0.20cvss 3.1epss 0.01

    A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow authenticated remote attackers to access data they are not…

  • CVE-2022-4102LowJan 9, 2023
    risk 0.20cvss 3.1epss 0.00

    The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts…

  • CVE-2021-33031LowJun 10, 2021
    risk 0.20cvss 3.1epss 0.01

    In LabCup before <v2_next_18022, it is possible to use the save API to perform unauthorized actions for users without access to user management in order to, after successful exploitation, gain access to a victim's account. A user without the user-management privilege can change…

  • CVE-2020-1720LowMar 17, 2020
    risk 0.20cvss 3.1epss 0.01

    A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database…

  • CVE-2026-49280medJul 15, 2026
    risk 0.19cvss epss

    A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default). ### Impact Unauthorized change in Issue workflow. ### Patches…

  • CVE-2026-49439medJul 6, 2026
    risk 0.19cvss epss

    # Summary The predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. The endpoint: ```text PUT /api/{realm}/asset/predicted/{assetId}/{attributeName} ``` accepts write requests from users lacking `write:assets`. The…

  • CVE-2026-2900LowMay 14, 2026
    risk 0.18cvss 2.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions…

  • CVE-2026-4916LowApr 8, 2026
    risk 0.18cvss 2.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to…

  • CVE-2026-32445LowMar 13, 2026
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5.

  • CVE-2026-27151LowFeb 26, 2026
    risk 0.18cvss 2.7epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` action only checked `can_move_posts?` on the source topic but never validated write permissions on the destination topic. This allowed TL4 users and category…