VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 148 of 209
  • CVE-2026-87598MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87577MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87561MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)

  • CVE-2026-87508MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87466MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-16941MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.

  • CVE-2026-82298MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • CVE-2026-82023MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question…

  • CVE-2026-82293MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their…

  • CVE-2026-78598MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single…

  • CVE-2026-72641MedSep 1, 2026
    risk 0.28cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the…

  • CVE-2026-80204MedAug 26, 2026
    risk 0.28cvss 5.4epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's security/permissions blueprint section is editable. Because the function performs raw…

  • CVE-2026-79262MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79261MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79248MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79238MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-79237MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79225MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via UI Interaction. (Chromium security severity: Low)

  • CVE-2026-79222MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium)

  • CVE-2026-79217MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)