VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 160 of 213
  • CVE-2026-1768MedFeb 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.

  • CVE-2026-22892MedFeb 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels…

  • CVE-2026-25568MedFeb 7, 2026
    risk 0.28cvss 4.3epss 0.00

    WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete…

  • CVE-2025-15342MedFeb 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Tanium addressed an improper access controls vulnerability in Reputation.

  • CVE-2025-67856MedFeb 3, 2026
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to,…

  • CVE-2025-15395MedFeb 2, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions beyond their expected capability.

  • CVE-2026-22624MedJan 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Due to inadequate access control, authenticated users of certain HIKSEMI NAS products can manipulate other users' file resources without proper authorization.

  • CVE-2025-15322MedJan 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Tanium addressed an improper access controls vulnerability in Tanium Server.

  • CVE-2026-24003MedJan 26, 2026
    risk 0.28cvss 4.3epss 0.00

    EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification including authentication, and send requests that transition to forbidden states relative to the current one, thereby updating the current…

  • CVE-2025-68140MedJan 21, 2026
    risk 0.28cvss 4.3epss 0.00

    EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has been verified, it is checked whether the submitted session ID matches the registered one. However, if no session has been registered, the default value is 0.…

  • CVE-2026-23496MedJan 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel Configurations." Testing…

  • CVE-2025-14943MedJan 10, 2026
    risk 0.28cvss 4.3epss 0.00

    The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.7.2. This is due to a misconfigured authorization check on the 'getShipItemFullText' function which only verifies that…

  • CVE-2025-66315MedJan 9, 2026
    risk 0.28cvss 4.3epss 0.00

    There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.

  • CVE-2026-22253MedJan 8, 2026
    risk 0.28cvss 5.4epss 0.00

    Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The…

  • CVE-2025-34467MedDec 31, 2025
    risk 0.28cvss 4.3epss 0.00

    ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the…

  • CVE-2025-15085MedDec 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java of the component Balance Handler. The manipulation results in…

  • CVE-2025-68422MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully…

  • CVE-2025-68386MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a…

  • CVE-2025-14318MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled.

  • CVE-2025-67490MedDec 10, 2025
    risk 0.28cvss 5.4epss 0.00

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This…