VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,238)

page 16 of 212
  • CVE-2022-0670CriJul 25, 2022
    risk 0.59cvss 9.1epss 0.01

    A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise…

  • CVE-2022-26629CriMar 24, 2022
    risk 0.59cvss 9.1epss 0.03

    An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.

  • CVE-2022-0482CriMar 9, 2022
    risk 0.59cvss 9.1epss 0.44

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

  • CVE-2021-39233CriNov 19, 2021
    risk 0.59cvss 9.1epss 0.02

    In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.

  • CVE-2021-41244CriNov 15, 2021
    risk 0.59cvss 9.1epss 0.03

    Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations.…

  • CVE-2021-30925CriAug 24, 2021
    risk 0.59cvss 9.1epss 0.01

    The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.

  • CVE-2021-30856CriAug 24, 2021
    risk 0.59cvss 9.1epss 0.01

    This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypass Privacy preferences.

  • CVE-2021-26040CriAug 24, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.

  • CVE-2021-20538CriMay 10, 2021
    risk 0.59cvss 9.1epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.

  • CVE-2020-29020CriMar 5, 2021
    risk 0.59cvss 9.1epss 0.02

    Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware.

  • CVE-2013-1350CriJan 30, 2020
    risk 0.59cvss 9.1epss 0.02

    Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities

  • CVE-2019-19597HigDec 5, 2019
    risk 0.59cvss 8.8epss 0.21

    D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.

  • CVE-2010-2548CriOct 31, 2019
    risk 0.59cvss 9.1epss 0.02

    IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.

  • CVE-2019-7258HigJul 2, 2019
    risk 0.59cvss 8.8epss 0.20

    Linear eMerge E3-Series devices allow Privilege Escalation.

  • CVE-2018-1245CriJul 13, 2018
    risk 0.59cvss 9.0epss 0.02

    RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security…

  • CVE-2018-7245CriApr 18, 2018
    risk 0.59cvss 9.1epss 0.01

    An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and…

  • CVE-2026-80515HigSep 3, 2026
    risk 0.58cvss —epss 0.00

    In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded,…

  • CVE-2026-27604CriJun 23, 2026
    risk 0.58cvss —epss 0.01

    FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the…

  • CVE-2026-46595CriMay 22, 2026
    risk 0.58cvss 10.0epss 0.01

    Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

  • CVE-2025-20701HigAug 4, 2025
    risk 0.58cvss 8.8epss 0.09

    In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.