VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 153 of 187
  • CVE-2025-43230MedJul 30, 2025
    risk 0.26cvss 4.0epss 0.00

    The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to access user-sensitive data.

  • CVE-2025-43197MedJul 30, 2025
    risk 0.26cvss 4.0epss 0.00

    This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

  • CVE-2024-47148MedDec 26, 2024
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2024-34652MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

  • CVE-2024-34650MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

  • CVE-2023-42569MedDec 5, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.

  • CVE-2023-42553MedNov 7, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.

  • CVE-2023-42541MedNov 7, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.

  • CVE-2023-22593MedJun 27, 2023
    risk 0.26cvss 4.0epss 0.00

    IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redis container which may provide elevated privileges. IBM X-Force ID: 244074.

  • CVE-2022-39914MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.

  • CVE-2022-39903MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.

  • CVE-2022-36009MedAug 19, 2022
    risk 0.26cvss 5.0epss 0.01

    gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixserverlib was failing to parse the `"events_default"` key of the `m.room.power_levels` event,…

  • CVE-2021-25506MedNov 5, 2021
    risk 0.26cvss 4.0epss 0.00

    Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.

  • CVE-2026-58156MedJul 29, 2026
    risk 0.25cvss 4.9epss 0.00

    Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15…

  • CVE-2026-8823LowJun 22, 2026
    risk 0.25cvss 3.8epss 0.00

    Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669

  • CVE-2026-8074LowJun 22, 2026
    risk 0.25cvss 3.8epss 0.00

    Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT…

  • CVE-2026-41280MedJun 17, 2026
    risk 0.25cvss 4.9epss 0.00

    Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

  • CVE-2026-41657MedMay 7, 2026
    risk 0.25cvss 4.9epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker permission check (isAdministratorUsers(), requiring only rol_edit_user=true) than the frontend UI (contacts.php) which correctly requires the stronger…

  • CVE-2025-68152MedApr 3, 2026
    risk 0.25cvss 4.9epss 0.00

    Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, it is possible that a compromised…

  • CVE-2026-32947MedMar 20, 2026
    risk 0.25cvss 4.9epss 0.00

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, a DNS over HTTPS (DoH) vulnerability allows attackers to bypass egress-policy: block network restrictions by tunneling exfiltrated data through permitted…