VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 147 of 209
  • CVE-2021-21411MedMar 26, 2021
    risk 0.29cvss 5.5epss 0.01

    OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the GitLab provider stopped working in the v7.0.0 release. Regardless of the flag settings, authorization…

  • CVE-2019-5533MedOct 29, 2019
    risk 0.29cvss 4.3epss 0.18

    In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provider accounts. Among the information is username, first and last name, phone…

  • CVE-2018-10910MedJan 28, 2019
    risk 0.29cvss 4.5epss 0.00

    A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51…

  • CVE-2018-5520MedMay 2, 2018
    risk 0.29cvss 4.4epss 0.01

    On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell (tmsh) may allow an administrative user to use the dig utility to gain unauthorized access to file system resources.

  • CVE-2026-1242MedSep 19, 2026
    risk 0.28cvss 4.3epss 0.00

    The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated…

  • CVE-2026-93379MedSep 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-92904MedSep 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against the record. An authenticated…

  • CVE-2026-92893MedSep 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An authenticated user whose host visibility…

  • CVE-2026-92894MedSep 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authenticated user with the…

  • CVE-2026-76863MedSep 15, 2026
    risk 0.28cvss 4.3epss 0.00

    Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access these QoS read routes to obtain live network…

  • CVE-2026-87107MedSep 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove…

  • CVE-2026-88894MedSep 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls…

  • CVE-2026-86773MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The existing check authorizes only the parent Predefined Kit (update…

  • CVE-2026-86760MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload before evaluating the canEditAuthFields…

  • CVE-2026-86755MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe-IT enforces on its own token…

  • CVE-2026-86752MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries…

  • CVE-2026-86747MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete…

  • CVE-2026-87046MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Tanium addressed an improper access controls vulnerability in Comply.

  • CVE-2026-14892MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Tanium addressed an improper access controls vulnerability in Tanium Server.

  • CVE-2026-87651MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)