VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 145 of 209
  • CVE-2024-12247MedDec 5, 2024
    risk 0.30cvss 4.6epss 0.00

    Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.

  • CVE-2024-44137MedOct 28, 2024
    risk 0.30cvss 4.6epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker with physical access may be able to share items from the lock screen.

  • CVE-2024-34642MedSep 4, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

  • CVE-2024-22133MedMar 12, 2024
    risk 0.30cvss 4.6epss 0.00

    SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This could lead to creation of request with incorrect approver causing low impact on Confidentiality and Integrity with no impact…

  • CVE-2023-38503MedJul 25, 2023
    risk 0.30cvss 5.7epss 0.01

    Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permission filters (i.e. `user_created IS $CURRENT_USER`) are not properly checked when using GraphQL subscription resulting in…

  • CVE-2021-22398MedAug 2, 2021
    risk 0.30cvss 4.6epss 0.00

    There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations. Affected…

  • CVE-2020-0473MedDec 15, 2020
    risk 0.30cvss 4.6epss 0.00

    In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical possession of the device to transfer files to it over Bluetooth, with no…

  • CVE-2020-7300MedAug 12, 2020
    risk 0.30cvss 4.6epss 0.01

    Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HTTP post messages.

  • CVE-2020-7921MedMay 6, 2020
    risk 0.30cvss 4.6epss 0.01

    Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2…

  • CVE-2017-16778MedDec 24, 2019
    risk 0.30cvss 4.6epss 0.01

    An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a restricted floor/level. By design, only a residential unit…

  • CVE-2019-5231MedNov 13, 2019
    risk 0.30cvss 4.6epss 0.00

    P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to…

  • CVE-2019-5220MedJul 10, 2019
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP…

  • CVE-2018-7988MedNov 27, 2018
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations.…

  • CVE-2018-7926MedNov 13, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID bound to the watch can bypass permission verification to…

  • CVE-2026-82920MedSep 14, 2026
    risk 0.29cvss 5.5epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy via a crafted PUT…

  • CVE-2026-19454MedAug 27, 2026
    risk 0.29cvss 4.4epss 0.00

    The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network,…

  • CVE-2026-48493MedJun 23, 2026
    risk 0.29cvss 5.5epss 0.00

    Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`,…

  • CVE-2026-56074MedJun 18, 2026
    risk 0.29cvss 5.5epss 0.00

    PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate…

  • CVE-2026-35370MedApr 22, 2026
    risk 0.29cvss 4.4epss 0.00

    The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and…

  • CVE-2026-5383MedApr 7, 2026
    risk 0.29cvss 4.4epss 0.00

    An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L (4.4 Medium). This…