VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 101 of 187
  • CVE-2026-32007MedMar 19, 2026
    risk 0.37cvss 6.8epss 0.00

    OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox access to modify files outside the workspace directory by exploiting inconsistent enforcement of workspace-only checks on mounted…

  • CVE-2026-32005MedMar 19, 2026
    risk 0.37cvss 6.8epss 0.00

    OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, and view_closed in shared workspace deployments. Unauthorized workspace members can bypass allowFrom restrictions and channel user…

  • CVE-2026-29607MedMar 19, 2026
    risk 0.37cvss 6.8epss 0.00

    OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence that allows attackers to bypass approval checks by persisting wrapper-level allowlist entries instead of validating inner executable intent. Remote attackers…

  • CVE-2025-68129MedDec 17, 2025
    risk 0.37cvss 6.8epss 0.00

    Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects…

  • CVE-2025-9955MedOct 16, 2025
    risk 0.37cvss 5.7epss 0.00

    An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs and user-store configuration. A low-privileged user can access log data and user-store…

  • CVE-2025-5187MedAug 27, 2025
    risk 0.37cvss 6.7epss 0.01

    A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is…

  • CVE-2024-49501MedNov 1, 2024
    risk 0.37cvss 5.7epss 0.00

    Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.

  • CVE-2024-47616MedOct 2, 2024
    risk 0.37cvss 6.8epss 0.01

    Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all persistent Pomerium application state. Requests to the databroker service API are authorized by the presence of a JSON Web Token (JWT) signed by a key known by…

  • CVE-2024-27915MedMar 6, 2024
    risk 0.37cvss 6.8epss 0.00

    Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of role permissions for webspaces which have a security system configured and permission check enabled. Webspaces without do not have…

  • CVE-2023-3444MedJul 13, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

  • CVE-2023-36829MedJul 6, 2023
    risk 0.37cvss 6.8epss 0.01

    Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly returns the `access-control-allow-credentials: true` HTTP header if the `Origin` request header ends with the…

  • CVE-2023-21422MedFeb 9, 2023
    risk 0.37cvss 5.7epss 0.00

    Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.

  • CVE-2022-2155MedJan 12, 2023
    risk 0.37cvss 5.7epss 0.00

    A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on the “Limited Engineer” role, granting it access to the embedded Power BI reports feature. An attacker that manages to…

  • CVE-2022-3881MedDec 12, 2022
    risk 0.37cvss 5.7epss 0.00

    The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it…

  • CVE-2022-24748MedMar 9, 2022
    risk 0.37cvss 6.8epss 0.01

    Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possible to modify customers and to create orders without App Permission. This issue is a result of improper api route checking. Users…

  • CVE-2021-21725MedMar 5, 2021
    risk 0.37cvss 5.7epss 0.00

    A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directories by performing specific operations, resulting in information leak. This affects: ZXHN H196Q V9.1.0C2.

  • CVE-2020-25655MedNov 9, 2020
    risk 0.37cvss 5.7epss 0.01

    An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user…

  • CVE-2020-15110MedJul 17, 2020
    risk 0.37cvss 6.8epss 0.01

    In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12.

  • CVE-2019-8512MedDec 18, 2019
    risk 0.37cvss 5.7epss 0.01

    This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise administrator to remotely wipe their device without appropriate disclosure.

  • CVE-2017-2673MedJul 19, 2018
    risk 0.37cvss 6.8epss 0.02

    An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.