VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,257)

page 115 of 213
  • CVE-2026-73469MedSep 16, 2026
    risk 0.38cvss 5.8epss 0.00

    When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and…

  • CVE-2026-55701MedSep 15, 2026
    risk 0.38cvss —epss 0.01

    The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go…

  • CVE-2026-80341MedSep 9, 2026
    risk 0.38cvss 5.9epss 0.00

    The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then…

  • CVE-2026-73310MedSep 8, 2026
    risk 0.38cvss 5.9epss 0.00

    XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can…

  • CVE-2026-62382MedAug 22, 2026
    risk 0.38cvss —epss 0.01

    PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true,…

  • CVE-2026-73049MedAug 14, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden access list instead of the visibility list when filtering backlinks. Anonymous readers can supply a publicly visible database row…

  • CVE-2026-73606MedAug 13, 2026
    risk 0.38cvss 5.8epss 0.00

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain…

  • CVE-2026-37171MedAug 7, 2026
    risk 0.38cvss 5.9epss 0.00

    A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.

  • CVE-2026-47998MedJul 14, 2026
    risk 0.38cvss 5.9epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's…

  • CVE-2026-47997MedJul 14, 2026
    risk 0.38cvss 5.9epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's…

  • CVE-2026-54698MedJul 7, 2026
    risk 0.38cvss 5.9epss 0.00

    Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table computed field (returning SETOF some_table) to infer row values that ought to be filtered for their role based on some_table's…

  • CVE-2026-53935MedJul 7, 2026
    risk 0.38cvss 6.9epss 0.00

    Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to…

  • CVE-2026-12352MedJul 7, 2026
    risk 0.38cvss 5.9epss 0.00

    This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

  • CVE-2026-50008MedJun 12, 2026
    risk 0.38cvss —epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured list of REST API routes. The check is…

  • CVE-2026-41470MedMay 19, 2026
    risk 0.38cvss 5.9epss 0.01

    LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a…

  • CVE-2026-5384MedApr 7, 2026
    risk 0.38cvss 5.8epss 0.00

    An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N…

  • CVE-2026-5378MedApr 7, 2026
    risk 0.38cvss 5.8epss 0.00

    An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (5.8…

  • CVE-2026-5374MedApr 7, 2026
    risk 0.38cvss 5.8epss 0.00

    An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A…

  • CVE-2025-66378MedDec 25, 2025
    risk 0.38cvss 5.9epss 0.00

    Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

  • CVE-2025-54265MedOct 14, 2025
    risk 0.38cvss 5.9epss 0.01

    Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit…