VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 143 of 209
  • CVE-2026-77454MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing filter or sort. …

  • CVE-2026-50550MedAug 19, 2026
    risk 0.31cvss 5.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint authorizes update access but does not…

  • CVE-2026-72792MedAug 12, 2026
    risk 0.31cvss 5.8epss 0.00

    SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from…

  • CVE-2026-73213MedAug 11, 2026
    risk 0.31cvss —epss 0.00

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an…

  • CVE-2026-35622MedApr 9, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook handling that accepts add-on principals outside intended deployment bindings. Attackers can bypass webhook authentication by providing non-deployment add-on…

  • CVE-2026-33424MedMar 21, 2026
    risk 0.31cvss 5.9epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an attacker can grant access to a private message topic through invites even after they lose access to that PM. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2…

  • CVE-2026-32039MedMar 19, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers to inherit elevated tool permissions through identifier collision attacks. Attackers can exploit untyped sender keys by forcing…

  • CVE-2026-32035MedMar 19, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag to default to true. Non-owner voice participants can exploit this omission to access owner-only tools including gateway and cron…

  • CVE-2026-21359MedMar 11, 2026
    risk 0.31cvss 4.7epss 0.00

    Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security…

  • CVE-2026-1553MedFeb 4, 2026
    risk 0.31cvss 4.8epss 0.00

    Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4.

  • CVE-2025-10015MedSep 16, 2025
    risk 0.31cvss —epss 0.00

    The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation…

  • CVE-2025-4975MedMay 22, 2025
    risk 0.31cvss —epss 0.00

    When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notification grants full access to the power settings of that device.

  • CVE-2025-21502MedJan 21, 2025
    risk 0.31cvss 4.8epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13,…

  • CVE-2022-30356MedOct 25, 2024
    risk 0.31cvss 4.7epss 0.00

    OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADMIN role privilege.

  • CVE-2024-20510MedSep 25, 2024
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before…

  • CVE-2024-34701MedMay 14, 2024
    risk 0.31cvss 5.9epss 0.01

    CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered as the requester of a specific wiki request if their local user ID on any wiki in a wiki farm matches the local ID of the requester at the wiki where the wiki…

  • CVE-2023-40315MedAug 17, 2023
    risk 0.31cvss 5.3epss 0.03

    In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily escalate their privileges to ROLE_ADMIN or any other role. The solution is to upgrade to Meridian 2023.1.5 or Horizon 32.0.2 or…

  • CVE-2023-25647MedAug 17, 2023
    risk 0.31cvss 4.7epss 0.00

    There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.

  • CVE-2023-39363MedAug 7, 2023
    risk 0.31cvss 5.9epss 0.01

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0, named re-entrancy locks are allocated incorrectly. Each function using a named re-entrancy lock gets a unique lock regardless of the key, allowing…

  • CVE-2023-2515MedMay 12, 2023
    risk 0.31cvss 4.7epss 0.00

    Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin