VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,257)

page 114 of 213
  • CVE-2026-26205HigFeb 19, 2026
    risk 0.39cvss —epss 0.01

    opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with…

  • CVE-2025-12149MedNov 14, 2025
    risk 0.39cvss —epss 0.00

    In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.

  • CVE-2025-48042HigSep 7, 2025
    risk 0.39cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ash: from 0.1.1 before 3.5.39.

  • CVE-2024-13947MedMay 22, 2025
    risk 0.39cvss 6.0epss 0.00

    Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

  • CVE-2024-22031higApr 25, 2025
    risk 0.39cvss —epss 0.01

    ### Impact A vulnerability has been identified within Rancher where a user with the ability to create a project, on a certain cluster, can create a project with the same name as an existing project in a different cluster. This results in the user gaining access to the other…

  • CVE-2024-4465MedSep 11, 2024
    risk 0.39cvss 6.0epss 0.00

    An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges learns how to create a specific application request, they…

  • CVE-2024-39323HigJul 2, 2024
    risk 0.39cvss 7.1epss 0.00

    aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end.…

  • CVE-2023-38488HigJul 27, 2023
    risk 0.39cvss 7.1epss 0.01

    Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update a Kirby…

  • CVE-2023-27899HigMar 10, 2023
    risk 0.39cvss 7.0epss 0.00

    Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file…

  • CVE-2022-2990HigSep 13, 2022
    risk 0.39cvss 7.1epss 0.00

    An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access…

  • CVE-2022-2989HigSep 13, 2022
    risk 0.39cvss 7.1epss 0.00

    An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access…

  • CVE-2022-27609MedApr 4, 2022
    risk 0.39cvss 6.0epss 0.00

    Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by users with Administrator privileges. This could result in a user disabling Forcepoint One Endpoint and the protection offered by it.

  • CVE-2022-27608MedApr 4, 2022
    risk 0.39cvss 6.0epss 0.00

    Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator privileges. This could result in a user disabling anti-tampering mechanisms which would then allow the user to disable Forcepoint One…

  • CVE-2022-0580HigFeb 14, 2022
    risk 0.39cvss 7.1epss 0.01

    Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.

  • CVE-2021-2471MedOct 20, 2021
    risk 0.39cvss 5.9epss 0.07

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2021-20188HigFeb 11, 2021
    risk 0.39cvss 7.0epss 0.00

    A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root…

  • CVE-2019-3403MedMay 22, 2019
    risk 0.39cvss 5.3epss 0.53

    The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

  • CVE-2019-3827HigMar 25, 2019
    risk 0.39cvss 7.0epss 0.00

    An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious…

  • CVE-2018-15468MedAug 17, 2018
    risk 0.39cvss 6.0epss 0.00

    An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do not. In particular, Branch Trace Store is not virtualised by the processor, and software has to be careful to configure it suitably…

  • CVE-2026-105805MedOct 6, 2026
    risk 0.38cvss —epss —

    Payload is a free and open source headless content management system. In versions before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query a readable collection, control its sorting, and select a protected field as the sort parameter can infer…