VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,244)

page 129 of 213
  • CVE-2026-32053MedMar 21, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per parse, allowing replay events to bypass manager dedupe checks. Attackers can replay Twilio webhook events to trigger duplicate or…

  • CVE-2026-32052MedMar 21, 2026
    risk 0.35cvss 6.4epss 0.02

    OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while…

  • CVE-2026-33428MedMar 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staff user with elevated group membership could access deleted posts belonging to any user due to an overly broad authorization check on the deleted posts index…

  • CVE-2026-32761MedMar 20, 2026
    risk 0.35cvss 6.5epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.0 and below contain a permission enforcement bypass which allows users who are denied download privileges (perm.download =…

  • CVE-2026-32758MedMar 20, 2026
    risk 0.35cvss 6.5epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.2 and below are vulnerable to Path Traversal through the resourcePatchHandler (http/resource.go). The destination path in…

  • CVE-2026-32027MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly eligible for group allowlist authorization checks. Attackers can exploit this cross-context authorization flaw by using a sender approved via DM…

  • CVE-2026-32021MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist implementation that accepts mutable sender display names instead of enforcing ID-only matching. An attacker can set a display name equal to an allowlisted ID…

  • CVE-2026-28282MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.00

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any private/restricted groups. Once…

  • CVE-2026-22170MedMar 18, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom configuration causes dmPolicy pairing and allowlist restrictions to be ineffective. Remote attackers can send direct messages to…

  • CVE-2026-22168MedMar 18, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execute arbitrary trailing arguments after cmd.exe /c while approval text reflects only a benign command. Attackers can smuggle…

  • CVE-2025-69196MedMar 16, 2026
    risk 0.35cvss 6.5epss 0.00

    FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the…

  • CVE-2026-32245MedMar 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authorization code is the same client the code was issued to. A malicious OIDC client operator can exchange another client's…

  • CVE-2026-32108MedMar 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the shr global-option). This vulnerability only applies when the shares feature is used for the specific purpose of creating a share of just a single file inside a…

  • CVE-2026-29195MedMar 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an admin-role user from assigning the super-admin role during account updates. While the code correctly blocks an admin from assigning…

  • CVE-2026-3103MedMar 4, 2026
    risk 0.35cvss 5.4epss 0.00

    A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL) allows a low-privileged user to cause data loss.

  • CVE-2025-13734MedMar 3, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized access permissions.

  • CVE-2026-25963MedFeb 26, 2026
    risk 0.35cvss 6.5epss 0.00

    Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within the same Fleet instance.…

  • CVE-2026-26328MedFeb 20, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts. Version 2026.2.14 fixes the issue.

  • CVE-2026-25566MedFeb 7, 2026
    risk 0.35cvss 5.4epss 0.00

    WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board,…

  • CVE-2026-23632MedFeb 6, 2026
    risk 0.35cvss 6.5epss 0.00

    Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write permissions and allows access with read permission only via repoAssignment(). After passing the permission check, PutContents()…