VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 457 of 463
  • CVE-2026-25808HigFeb 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This…

  • CVE-2026-2208MedFeb 8, 2026
    risk 0.00cvss 4.3epss 0.00

    A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be initiated remotely. Upgrading to version…

  • CVE-2026-1897MedFeb 5, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attack may be performed from…

  • CVE-2026-24139MedJan 24, 2026
    risk 0.00cvss 6.5epss 0.00

    MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard against authorization bypass, allowing guest users to download the complete application database. The application fails to properly validate user permissions on…

  • CVE-2026-24055MedJan 22, 2026
    risk 0.00cvss 5.3epss 0.00

    Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates Slack OAuth using a projectId provided by the client without authentication or authorization. The projectId is preserved…

  • CVE-2025-69221MedJan 7, 2026
    risk 0.00cvss 4.3epss 0.00

    LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when querying agent permissions. An authenticated attacker can read the permissions of arbitrary agents, even if they have no permissions for this agent. LibreChat…

  • CVE-2025-69220HigJan 7, 2026
    risk 0.00cvss 7.1epss 0.00

    LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by…

  • CVE-2025-64520MedDec 16, 2025
    risk 0.00cvss 6.5epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.

  • CVE-2025-66022CriNov 26, 2025
    risk 0.00cvss 9.6epss 0.01

    FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension framework permits untrusted extension code to execute arbitrary system commands on the server when a lifecycle hook is invoked,…

  • CVE-2025-62712CriOct 30, 2025
    risk 0.00cvss 9.6epss 0.00

    JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, non-privileged user can retrieve connection tokens belonging to other users via the super-connection…

  • CVE-2025-59413MedSep 22, 2025
    risk 0.00cvss 6.5epss 0.00

    CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the force_unsubscribe parameter in the POST request to…

  • CVE-2025-59475MedSep 17, 2025
    risk 0.00cvss 4.3epss 0.00

    Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options…

  • CVE-2025-43720MedJul 21, 2025
    risk 0.00cvss 6.5epss 0.00

    Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.

  • CVE-2025-53825CriJul 14, 2025
    risk 0.00cvss 9.4epss 0.01

    Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to execute arbitrary code and access sensitive environment variables by simply opening a pull request on a…

  • CVE-2025-53374MedJul 7, 2025
    risk 0.00cvss 4.3epss 0.00

    Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organization by directly…

  • CVE-2025-5410MedJun 1, 2025
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability affects the function session_start_response of the file src/mist/api/auth/middleware.py. The manipulation leads to cross-site request forgery. The attack can…

  • CVE-2025-47792MedMay 16, 2025
    risk 0.00cvss 5.0epss 0.00

    Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an…

  • CVE-2025-24021MedMay 14, 2025
    risk 0.00cvss 5.0epss 0.00

    iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.

  • CVE-2025-43862HigApr 25, 2025
    risk 0.00cvss 7.6epss 0.00

    Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allows non-admin users to make…

  • CVE-2025-32045MedApr 25, 2025
    risk 0.00cvss 5.3epss 0.00

    A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.