VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,244)

page 124 of 213
  • CVE-2023-50460MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.

  • CVE-2023-50459MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.

  • CVE-2026-88006MedSep 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback…

  • CVE-2026-88005MedSep 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback…

  • CVE-2026-87014MedSep 9, 2026
    risk 0.35cvss 6.5epss 0.01

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's database role without invalidating the user…

  • CVE-2026-87575MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87540MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-33391MedSep 8, 2026
    risk 0.35cvss 5.4epss 0.00

    An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access control of the web management interface and…

  • CVE-2026-53769MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.00

    Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as…

  • CVE-2026-85697MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.00

    Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on…

  • CVE-2026-85166MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.00

    n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/updating a workflow via the REST API, Public…

  • CVE-2026-78609MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate…

  • CVE-2026-82634MedAug 30, 2026
    risk 0.35cvss 6.5epss 0.00

    Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings. Attackers with print permission on any document can execute arbitrary…

  • CVE-2026-82272MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared…

  • CVE-2026-62904MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-61783MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege user can read the cluster secret from the manager configuration because the logic that masks…

  • CVE-2026-81729MedAug 27, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_document() with the mode argument 'read' when handling DELETE /api/index.php/documents, while…

  • CVE-2026-78898MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79673MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with an admin's profile:read access token can change the admin's password and login to obtain an unrestricted…

  • CVE-2026-71510MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restrictions. Attackers can…