VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 155 of 187
  • CVE-2026-27447MedApr 3, 2026
    risk 0.24cvss 4.8epss 0.00

    OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The…

  • CVE-2026-33869MedMar 27, 2026
    risk 0.24cvss 4.8epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on…

  • CVE-2026-4363LowMar 25, 2026
    risk 0.24cvss 3.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources due to improper caching of…

  • CVE-2026-32065MedMar 21, 2026
    risk 0.24cvss 4.8epss 0.00

    OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval identity while trimming argv token whitespace, but runtime execution uses raw argv. An attacker can craft a trailing-space…

  • CVE-2025-59376LowSep 15, 2025
    risk 0.24cvss 3.7epss 0.00

    feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete…

  • CVE-2025-47937LowMay 20, 2025
    risk 0.24cvss 3.7epss 0.00

    TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, when performing a database query involving multiple tables through the database abstraction…

  • CVE-2025-32093MedApr 14, 2025
    risk 0.24cvss 4.7epss 0.00

    Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized…

  • CVE-2024-31990MedApr 15, 2024
    risk 0.24cvss 4.8epss 0.00

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit resources which should only be mutable via gitops. This vulenrability is fixed in 2.10.7, 2.9.12, and…

  • CVE-2023-3509LowFeb 21, 2024
    risk 0.24cvss 3.7epss 0.00

    An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible…

  • CVE-2022-39352MedNov 8, 2022
    risk 0.24cvss 4.8epss 0.00

    OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization bypass under certain conditions. You are affected by this vulnerability if you added a tuple with a wildcard (*) assigned to a…

  • CVE-2021-39138MedAug 19, 2021
    risk 0.24cvss 4.8epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup users and also allow users to login anonymously. Prior to version 4.5.1, when an anonymous user is first signed up using REST, the…

  • CVE-2017-12196MedApr 18, 2018
    risk 0.24cvss 4.8epss 0.02

    undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM…

  • CVE-2026-47086LowJul 16, 2026
    risk 0.23cvss 3.5epss 0.00

    An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading…

  • CVE-2025-62487LowJan 9, 2026
    risk 0.23cvss 3.5epss 0.00

    On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked correctly with the proper security levels. The regression was traced back to a change in May 2025, which was meant to allow file uploads to be shared among…

  • CVE-2025-64746MedNov 13, 2025
    risk 0.23cvss 4.6epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions when a field is deleted. When a field is removed from a collection, its reference in the permissions table…

  • CVE-2025-59451LowOct 6, 2025
    risk 0.23cvss 3.5epss 0.00

    The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.

  • CVE-2020-9081LowDec 27, 2024
    risk 0.23cvss 3.5epss 0.00

    There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) …

  • CVE-2023-0120LowSep 1, 2023
    risk 0.23cvss 3.5epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an…

  • CVE-2023-3613LowJul 17, 2023
    risk 0.23cvss 3.5epss 0.00

    Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowing guest accounts to be added or invited to channels by default.

  • CVE-2022-46169CriKEVDec 5, 2022
    risk 0.23cvss 9.8epss 1.00

    Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if…