VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 129 of 187
  • CVE-2017-16778MedDec 24, 2019
    risk 0.30cvss 4.6epss 0.01

    An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a restricted floor/level. By design, only a residential unit…

  • CVE-2019-5231MedNov 13, 2019
    risk 0.30cvss 4.6epss 0.00

    P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to…

  • CVE-2019-5220MedJul 10, 2019
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP…

  • CVE-2018-7988MedNov 27, 2018
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations.…

  • CVE-2018-7926MedNov 13, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID bound to the watch can bypass permission verification to…

  • CVE-2026-48493MedJun 23, 2026
    risk 0.29cvss 5.5epss 0.00

    Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`,…

  • CVE-2026-56074MedJun 18, 2026
    risk 0.29cvss 5.5epss 0.00

    PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate…

  • CVE-2026-35370MedApr 22, 2026
    risk 0.29cvss 4.4epss 0.00

    The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and…

  • CVE-2026-5383MedApr 7, 2026
    risk 0.29cvss 4.4epss 0.00

    An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L (4.4 Medium). This…

  • CVE-2026-28716MedMar 6, 2026
    risk 0.29cvss 4.4epss 0.00

    Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2025-43336MedNov 4, 2025
    risk 0.29cvss 4.4epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app with root privileges may be able to access private information.

  • CVE-2025-54569MedJul 28, 2025
    risk 0.29cvss 4.5epss 0.00

    In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation.

  • CVE-2025-21568MedJan 21, 2025
    risk 0.29cvss 4.5epss 0.00

    Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security). The supported version that is affected is 11.2.19.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP…

  • CVE-2025-21519MedJan 21, 2025
    risk 0.29cvss 4.4epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network…

  • CVE-2024-39322MedJul 2, 2024
    risk 0.29cvss 5.5epss 0.00

    aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend.…

  • CVE-2024-5258MedMay 23, 2024
    risk 0.29cvss 4.4epss 0.00

    An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

  • CVE-2024-23451MedMar 27, 2024
    risk 0.29cvss 4.4epss 0.00

    Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote…

  • CVE-2023-41779MedJan 3, 2024
    risk 0.29cvss 4.4epss 0.00

    There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.

  • CVE-2023-7047MedDec 21, 2023
    risk 0.29cvss 4.4epss 0.00

    Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.…

  • CVE-2023-5995MedDec 1, 2023
    risk 0.29cvss 4.4epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal…