VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,257)

page 111 of 213
  • CVE-2021-41189HigOct 29, 2021
    risk 0.40cvss 7.2epss 0.02

    DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in…

  • CVE-2021-3457MedMay 12, 2021
    risk 0.40cvss 6.1epss 0.00

    An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources…

  • CVE-2021-21367MedMar 12, 2021
    risk 0.40cvss 6.1epss 0.01

    Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted,…

  • CVE-2019-11724MedJul 23, 2019
    risk 0.40cvss 6.1epss 0.01

    Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability…

  • CVE-2026-43976HigOct 7, 2026
    risk 0.39cvss 7.1epss —

    wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote`…

  • CVE-2026-102335HigSep 28, 2026
    risk 0.39cvss 7.1epss 0.00

    Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary…

  • CVE-2026-100392HigSep 28, 2026
    risk 0.39cvss —epss 0.00

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary…

  • CVE-2026-57449HigSep 25, 2026
    risk 0.39cvss —epss 0.00

    Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TOKEN` is configured, the proxy…

  • CVE-2026-61672HigSep 18, 2026
    risk 0.39cvss 7.1epss 0.00

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes byte-order sorting. When an…

  • CVE-2026-59965HigSep 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while…

  • CVE-2026-19816HigSep 14, 2026
    risk 0.39cvss 7.1epss 0.00

    A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role…

  • CVE-2026-78134HigSep 11, 2026
    risk 0.39cvss 7.1epss 0.00

    strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

  • CVE-2026-87803HigSep 10, 2026
    risk 0.39cvss 7.1epss 0.00

    An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines…

  • CVE-2026-87998HigSep 9, 2026
    risk 0.39cvss 7.1epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge base but then removed its administrator-owned…

  • CVE-2026-80223HigAug 30, 2026
    risk 0.39cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver authorizes each notification payload in…

  • CVE-2026-77611HigAug 26, 2026
    risk 0.39cvss 7.1epss 0.00

    SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object outside that scope by calling PutObjectAcl on the key it is allowed to access.…

  • CVE-2026-66003HigAug 26, 2026
    risk 0.39cvss —epss 0.00

    Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows a user to read data from Linked DocTypes that they are not authorized to access. When a document references another…

  • CVE-2026-17183HigAug 19, 2026
    risk 0.39cvss 7.1epss 0.00

    An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through…

  • CVE-2026-18674HigAug 17, 2026
    risk 0.39cvss —epss 0.01

    On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global…

  • CVE-2026-49989HigAug 14, 2026
    risk 0.39cvss —epss 0.00

    CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s. CrateDB has two ways to access blob…