VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 102 of 187
  • CVE-2026-62775MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

  • CVE-2026-21077MedAug 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

  • CVE-2026-21076MedAug 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

  • CVE-2026-18934MedAug 10, 2026
    risk 0.36cvss 5.5epss 0.00

    The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import…

  • CVE-2026-18954MedAug 5, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass…

  • CVE-2026-65835MedJul 30, 2026
    risk 0.36cvss 6.6epss 0.00

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not…

  • CVE-2026-49219MedJun 10, 2026
    risk 0.36cvss 5.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue…

  • CVE-2026-2462MedMar 16, 2026
    risk 0.36cvss 6.6epss 0.00

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration…

  • CVE-2026-26949MedMar 4, 2026
    risk 0.36cvss 5.5epss 0.00

    Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2026-20624MedFeb 11, 2026
    risk 0.36cvss 5.5epss 0.00

    An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.

  • CVE-2025-13813MedDec 1, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The attack can be initiated remotely. The attack's…

  • CVE-2025-43397MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to cause a denial-of-service.

  • CVE-2025-26442MedSep 4, 2025
    risk 0.36cvss 5.5epss 0.00

    In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2025-43251MedJul 30, 2025
    risk 0.36cvss 5.5epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.6. A local attacker may gain access to Keychain items.

  • CVE-2025-50085MedJul 15, 2025
    risk 0.36cvss 5.5epss 0.00

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2025-30739MedJul 15, 2025
    risk 0.36cvss 5.5epss 0.00

    Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to…

  • CVE-2024-8270MedJun 11, 2025
    risk 0.36cvss 5.5epss 0.00

    The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling the exploitation or abuse of permissions specified in its entitlements (e.g., microphone, camera, automation, network client).…

  • CVE-2025-46834MedMay 15, 2025
    risk 0.36cvss epss 0.00

    Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the 2.x branch prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, owners of Modular Accounts can grant session keys (scoped external keys) to external…

  • CVE-2025-30440MedMay 12, 2025
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to bypass ASLR.

  • CVE-2024-12862MedApr 21, 2025
    risk 0.36cvss epss 0.00

    Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to remove external collaborators.This issue affects Content Server: 20.2-24.4.