VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,244)

page 139 of 213
  • CVE-2026-92992MedSep 17, 2026
    risk 0.34cvss 6.3epss 0.00

    A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authorization. Remote exploitation of the attack is…

  • CVE-2026-52819MedSep 15, 2026
    risk 0.34cvss —epss 0.01

    Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a ROLE_TEAMLEAD requester leads a team…

  • CVE-2026-90806MedSep 14, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be…

  • CVE-2023-50462MedSep 14, 2026
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading…

  • CVE-2026-81905MedSep 11, 2026
    risk 0.34cvss —epss 0.00

    Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone and does not verify its type. As a…

  • CVE-2026-88860MedSep 10, 2026
    risk 0.34cvss 6.3epss 0.00

    Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked to perform unauthorized actions like…

  • CVE-2026-87594MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-86274MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication…

  • CVE-2025-15691MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user…

  • CVE-2026-78153MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.

  • CVE-2025-8945MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.

  • CVE-2025-15490MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs

  • CVE-2025-15489MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content

  • CVE-2026-81158MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.

  • CVE-2026-84303MedSep 1, 2026
    risk 0.34cvss —epss 0.00

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a…

  • CVE-2026-82879MedAug 31, 2026
    risk 0.34cvss 6.3epss 0.00

    DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused against another (ShareTicketManage.validateTicket / POST /de2api/share/proxyInfo).…

  • CVE-2026-68951MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data.

  • CVE-2026-17559MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route,…

  • CVE-2026-55163MedAug 18, 2026
    risk 0.34cvss 6.3epss 0.00

    Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(role_id), which allowed either an administrator or any existing member of the target role. The handler passed data["users"] and…

  • CVE-2026-11817MedAug 17, 2026
    risk 0.34cvss —epss 0.00

    This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?ac…