VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,244)

page 125 of 213
  • CVE-2026-67204MedAug 24, 2026
    risk 0.35cvss 5.4epss 0.00

    BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints.…

  • CVE-2026-76342MedAug 19, 2026
    risk 0.35cvss 5.4epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store risky Search Processing Language (SPL) commands in a Table Editor dataset and share the dataset. A user who holds the "admin" Splunk role triggers the…

  • CVE-2026-76341MedAug 19, 2026
    risk 0.35cvss 5.4epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a Table Editor dataset and share the dataset. A user who holds the "admin" Splunk role triggers…

  • CVE-2026-49976MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. app/Importer/UserImporter.php applies the…

  • CVE-2026-19670MedAug 18, 2026
    risk 0.35cvss 5.4epss 0.00

    Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx…

  • CVE-2026-9859MedAug 17, 2026
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted…

  • CVE-2026-73059MedAug 16, 2026
    risk 0.35cvss 6.5epss 0.00

    stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requiring ReadMessageHistory. Attackers with ViewChannel access but ReadMessageHistory denied can retrieve individual message content…

  • CVE-2026-72673MedAug 13, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it…

  • CVE-2026-57897MedAug 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

  • CVE-2026-53786MedAug 13, 2026
    risk 0.35cvss 6.5epss 0.00

    rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation…

  • CVE-2026-73265MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals without historical-version permission to…

  • CVE-2026-47230MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same root-cause shape as the cross-folder move bug (`05-documents-cross-folder-move-idor.md`): the top-level rights check at lines 79-89…

  • CVE-2026-47227MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor administers. The follow-up "is this specific category editable by me" check at lines 56-61…

  • CVE-2026-18698MedAug 11, 2026
    risk 0.35cvss 5.4epss 0.00

    An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain…

  • CVE-2026-58139MedAug 3, 2026
    risk 0.35cvss 6.5epss 0.01

    The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load_aws_credentials function with the redact_secret parameter set to false,…

  • CVE-2026-68930MedAug 3, 2026
    risk 0.35cvss 6.5epss 0.00

    Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version…

  • CVE-2026-16064MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and…

  • CVE-2026-2411MedAug 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to BT_GATT_PERM_READ, and a Characteristic Value attribute that carries the application-specified security permissions (e.g.…

  • CVE-2026-10031MedJul 30, 2026
    risk 0.35cvss 5.4epss 0.00

    SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions…

  • CVE-2026-41187MedJul 30, 2026
    risk 0.35cvss 6.5epss 0.00

    Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection…