VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 170 of 187
  • CVE-2025-3611LowMay 30, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct…

  • CVE-2025-1792LowMay 30, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members…

  • CVE-2025-41423LowApr 24, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the…

  • CVE-2025-2424LowApr 14, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.

  • CVE-2024-47780LowOct 8, 2024
    risk 0.13cvss 3.1epss 0.00

    TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody."…

  • CVE-2024-44114LowSep 10, 2024
    risk 0.13cvss 2.0epss 0.00

    SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that reveals data over the network. This results in a minimal impact on confidentiality of the application.

  • CVE-2023-3511LowDec 15, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private…

  • CVE-2023-3485LowJun 30, 2023
    risk 0.13cvss 3.0epss 0.00

    Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request. Creation of this task token must be done outside of the normal Temporal server…

  • CVE-2021-39164LowAug 31, 2021
    risk 0.13cvss 3.1epss 0.01

    Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerability is limited to rooms…

  • CVE-2021-39163LowAug 31, 2021
    risk 0.13cvss 3.1epss 0.01

    Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limited to homeservers where…

  • CVE-2025-0885LowJul 3, 2025
    risk 0.12cvss epss 0.00

    Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow unauthorized access to calendar items marked private. This issue affects GroupWise versions 7 through 17.5,…

  • CVE-2026-32946LowMar 20, 2026
    risk 0.11cvss 2.7epss 0.00

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, the Harden-Runner that allows bypass of the egress-policy: block network restriction using DNS queries over TCP. Egress policies are enforced on GitHub…

  • CVE-2026-32717LowMar 16, 2026
    risk 0.11cvss 2.7epss 0.00

    AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended users on the normal JWT-backed session path, but it does not block them on the…

  • CVE-2025-11888LowOct 25, 2025
    risk 0.11cvss 2.7epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up…

  • CVE-2025-4563LowJun 23, 2025
    risk 0.11cvss 2.7epss 0.01

    A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status…

  • CVE-2022-0824HigMar 2, 2022
    risk 0.11cvss 8.8epss 0.97

    Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

  • CVE-2026-32058LowMar 21, 2026
    risk 0.10cvss 2.6epss 0.00

    OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of previously approved requests with modified environment variables. Attackers with access to an approval id can exploit this by…

  • CVE-2026-66000LowAug 7, 2026
    risk 0.08cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by…

  • CVE-2025-27512LowMar 17, 2025
    risk 0.07cvss epss 0.00

    Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy` to deploy updates to the system and `org.projectatomic.rpmostree1.finalize-deployment` to reboot…

  • CVE-2026-46549LowJun 23, 2026
    risk 0.06cvss 2.0epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user, but the ACL middleware never consulted either. An OAuth token issued with a restricted scope (e.g.…