VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 171 of 187
  • CVE-2021-21276CriFeb 1, 2021
    risk 0.04cvss 9.3epss 0.07

    Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. This vulnerability exists regardless of users' settings. If an…

  • CVE-2018-18955HigNov 16, 2018
    risk 0.04cvss 7.0epss 0.08

    In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass…

  • CVE-2007-2586May 10, 2007
    risk 0.04cvss epss 0.14

    The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY…

  • CVE-2021-43858HigDec 27, 2021
    risk 0.03cvss 8.8epss 0.35

    MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version…

  • CVE-2022-39214CriMar 14, 2023
    risk 0.02cvss 9.6epss 0.26

    Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.

  • CVE-2026-47997MedJul 14, 2026
    risk 0.01cvss 5.9epss 0.09

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's…

  • CVE-2026-48794LowJun 19, 2026
    risk 0.01cvss epss 0.00

    Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through 4.39.19, due to lack of canonicalization of domains in very specific edge cases, an…

  • CVE-2025-14986LowDec 30, 2025
    risk 0.01cvss epss 0.00

    When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows…

  • CVE-2021-42192HigMay 4, 2022
    risk 0.01cvss 8.8epss 0.10

    Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

  • CVE-2026-73692Aug 18, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-71201MedAug 5, 2026
    risk 0.00cvss 5.0epss 0.00

    In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.

  • CVE-2026-71192MedAug 5, 2026
    risk 0.00cvss epss 0.00

    In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, causing…

  • CVE-2026-70471HigAug 4, 2026
    risk 0.00cvss epss 0.00

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active…

  • CVE-2026-64630MedAug 4, 2026
    risk 0.00cvss epss 0.00

    A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.

  • CVE-2026-15254MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to…

  • CVE-2026-16540HigAug 2, 2026
    risk 0.00cvss 7.5epss 0.00

    The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions,…

  • CVE-2026-16064MedAug 2, 2026
    risk 0.00cvss 5.4epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and…

  • CVE-2026-14929MedJul 31, 2026
    risk 0.00cvss 4.3epss 0.00

    The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.

  • CVE-2026-10031MedJul 30, 2026
    risk 0.00cvss 4.2epss 0.00

    SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions…

  • CVE-2026-14923MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an operator-precedence flaw in its authorization check. An authenticated user holding only the…